[Pkg-phototools-devel] Bug#731237: openjpeg: CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 CVE-2013-6054

2013-12-03 Thread Salvatore Bonaccorso
Package: openjpeg Severity: grave Tags: security upstream patch Hi This is to track the issues released with DSA-2808-1 for openjpeg in the BTS. See http://lists.debian.org/debian-security-announce/2013/msg00222.html http://www.debian.org/security/2013/dsa-2808 Regards, Salvatore

[Pkg-phototools-devel] Bug#743372: openjpeg: CVE-2014-0158: Heap-based buffer overflow in JPEG2000 image tile decoder

2014-04-02 Thread Salvatore Bonaccorso
Source: openjpeg Severity: grave Tags: security upstream Hi, the following vulnerability was published for openjpeg. CVE-2014-0158[0]: Heap-based buffer overflow in JPEG2000 image tile decoder More information are on the Red Hat bugzilla[1]. If you fix the vulnerability please also make sure

[Pkg-phototools-devel] Bug#786792: darktable: CVE-2015-3885: input sanitization flaw leading to buffer overflow

2015-05-25 Thread Salvatore Bonaccorso
Source: darktable Version: 1.0.4-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for darktable. CVE-2015-3885[0]: | Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier | allows remote attackers to cause a denial of service (crash)

[Pkg-phototools-devel] Bug#801700: optipng: CVE-2015-7802: Buffer overflow in global memory

2015-10-13 Thread Salvatore Bonaccorso
Source: optipng Version: 0.7.5-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for optipng. CVE-2015-7802[0]: Buffer overflow in global memory If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures)

[Pkg-phototools-devel] Bug#820068: optipng: diff for NMU version 0.7.5-1.1

2016-04-08 Thread Salvatore Bonaccorso
Hi The used patch took into account as well the fixed from upstream bugs 56 and 57, which correspond to CVE-2016-3981 and CVE-2016-3982. At the time of writing those two CVEs were not yet assigned. So once accepted into the archive, I will update as well the information for those CVEs. Regards,

[Pkg-phototools-devel] Bug#820068: optipng: diff for NMU version 0.7.5-1.1

2016-04-07 Thread Salvatore Bonaccorso
@@ +optipng (0.7.5-1.1) unstable; urgency=high + + * Non-maintainer upload. + * CVE-2016-2191: Invalid write while processing delta escapes without +any boundary checking (Patch from Moritz Muehlenhoff from the jessie- +security upload) (Closes: #820068) + + -- Salvatore Bonaccorso <

[Pkg-phototools-devel] Bug#820068: optipng: CVE-2016-2191: Invalid write while processing delta escapes without any boundary checking

2016-04-05 Thread Salvatore Bonaccorso
Source: optipng Version: 0.6.4-1 Severity: important Tags: security upstream fixed-upstream Forwarded: https://sourceforge.net/p/optipng/bugs/59/ Hi, the following vulnerability was published for optipng and is fixed in 0.7.6 upstream. CVE-2016-2191[0]: Invalid write while processing delta

[Pkg-phototools-devel] Bug#800149: openjpeg2: Use-after-free in opj_j2k_write_mco

2016-05-12 Thread Salvatore Bonaccorso
Control: retitle -1 openjpeg2: CVE-2015-8871: Use-after-free in opj_j2k_write_mco Hi, On Sun, Sep 27, 2015 at 01:54:25PM +0200, Salvatore Bonaccorso wrote: > Source: openjpeg2 > Version: 2.1.0-2 > Severity: important > Tags: security upstream patch fixed-upstream > Forwarded: htt

[Pkg-phototools-devel] Bug#831814: lepton: CVE-2016-6234 CVE-2016-6235 CVE-2016-6236 CVE-2016-6237 CVE-2016-6238

2016-07-19 Thread Salvatore Bonaccorso
Source: lepton Version: 1.0-2 Severity: grave Tags: security upstream Justification: user security hole Hi, Multiple issues were found in lepton. The CVE request was at http://www.openwall.com/lists/oss-security/2016/07/17/1 referencing https://github.com/dropbox/lepton/issues/26 (note to

[Pkg-phototools-devel] Bug#851422: openjpeg2: diff for NMU version 2.1.2-1.1

2017-01-22 Thread Salvatore Bonaccorso
-9572: NULL pointer dereference in input decoding +CVE-2016-9573: Heap out-of-bounds read due to insufficient check in +imagetopnm(). (Closes: #851422) + + -- Salvatore Bonaccorso <car...@debian.org> Sun, 22 Jan 2017 14:18:13 +0100 + openjpeg2 (2.1.2-1) unstable; urgency=medium

[Pkg-phototools-devel] Bug#837604: openjpeg2: CVE-2016-7163: Integer overflow in opj_pi_create_decode

2016-09-12 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: grave Tags: security upstream patch Control: fixed -1 2.1.0-2+deb8u1 Hi, the following vulnerability was published for openjpeg2. CVE-2016-7163[0]: Integer overflow in opj_pi_create_decode If you fix the vulnerability please also make sure to

[Pkg-phototools-devel] Bug#844554: openjpeg2: CVE-2016-9115

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/858 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9115[0]: | Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in |

[Pkg-phototools-devel] Bug#844555: openjpeg2: CVE-2016-9116

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/859 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9116[0]: | NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in |

[Pkg-phototools-devel] Bug#844553: openjpeg2: CVE-2016-9114

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/857 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9114[0]: | There is a NULL Pointer Access in function imagetopnm of |

[Pkg-phototools-devel] Bug#844552: openjpeg2: CVE-2016-9113

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/856 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9113[0]: | There is a NULL pointer dereference in function imagetobmp of |

[Pkg-phototools-devel] Bug#844551: openjpeg2: CVE-2016-9112

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/855 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9112[0]: | Floating Point Exception (aka FPE or divide by zero) in | opj_pi_next_cprl

[Pkg-phototools-devel] Bug#844557: openjpeg2: CVE-2016-9118

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/861 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9118[0]: | Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of |

[Pkg-phototools-devel] Bug#844556: openjpeg2: CVE-2016-9117

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/860 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9117[0]: | NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in |

[Pkg-phototools-devel] Bug#859714: lepton: CVE-2017-7448

2017-04-06 Thread Salvatore Bonaccorso
Source: lepton Version: 1.2.1-2 Severity: important Tags: security upstream patch Forwarded: https://github.com/dropbox/lepton/issues/86 Hi, the following vulnerability was published for lepton. CVE-2017-7448[0]: | The allocate_channel_framebuffer function in uncompressed_components.hh | in

[Pkg-phototools-devel] Bug#860367: feh: CVE-2017-7875

2017-04-15 Thread Salvatore Bonaccorso
Source: feh Version: 2.12-1 Severity: normal Tags: upstream security patch fixed-upstream Hi, the following vulnerability was published for fehl. CVE-2017-7875[0]: | In wallpaper.c in feh before v2.18.3, if a malicious client pretends to | be the E17 window manager, it is possible to trigger an

[Pkg-phototools-devel] Bug#862446: lepton: CVE-2017-8891

2017-05-12 Thread Salvatore Bonaccorso
Source: lepton Version: 1.2.1-2 Severity: important Tags: upstream security Forwarded: https://github.com/dropbox/lepton/issues/87 Hi, the following vulnerability was published for lepton. CVE-2017-8891[0]: | Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a | malformed lepton

[Pkg-phototools-devel] Bug#876535: openjpeg2: Incoorporate lost changelogs (and possibly changes) for NMUs 2.1.2-1.1, 2.1.2-1.2 and 2.1.2-1.3

2017-09-23 Thread Salvatore Bonaccorso
CVE-2016-9573: Heap out-of-bounds read due to insufficient check in -imagetopnm(). (Closes: #851422) - - -- Salvatore Bonaccorso <car...@debian.org> Sun, 22 Jan 2017 14:18:13 +0100 + -- Mathieu Malaterre <ma...@debian.org> Fri, 22 Sep 2017 21:51:36 +0200 openjpeg2 (2.1.2-1)

[Pkg-phototools-devel] Bug#878551: openexr: CVE-2017-14988

2017-10-14 Thread Salvatore Bonaccorso
Source: openexr Version: 2.2.0-11 Severity: important Tags: security upstream Forwarded: https://github.com/openexr/openexr/issues/248 Hi, the following vulnerability was published for openexr. CVE-2017-14988[0]: | Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote |

[Pkg-phototools-devel] Bug#874430: openjpeg2: CVE-2017-14151: heap-based buffer overflow in opj_mqc_flush

2017-09-05 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1.3 Severity: grave Tags: security upstream patch Forwarded: https://github.com/uclouvain/openjpeg/issues/982 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14151[0]: | An off-by-one error was discovered in |

[Pkg-phototools-devel] Bug#874431: openjpeg2: CVE-2017-14152: heap-based buffer overflow in opj_write_bytes_LE

2017-09-05 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1.3 Severity: grave Tags: upstream patch security Forwarded: https://github.com/uclouvain/openjpeg/issues/985 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14152[0]: | A mishandled zero case was discovered in opj_j2k_set_cinema_parameters

[Pkg-phototools-devel] Bug#877352: openexr:CVE-2017-12596

2017-09-30 Thread Salvatore Bonaccorso
Source: openexr Version: 2.2.0-11.1 Severity: important Tags: upstream security Forwarded: https://github.com/openexr/openexr/issues/238 Hi, the following vulnerability was published for openexr, filling this bug to track the upstream issue at [1]. CVE-2017-12596[0]: | In OpenEXR 2.2.0, a

[Pkg-phototools-devel] Bug#876535: openjpeg2: Incoorporate lost changelogs (and possibly changes) for NMUs 2.1.2-1.1, 2.1.2-1.2 and 2.1.2-1.3

2017-09-25 Thread Salvatore Bonaccorso
Hi Mathieu, On Mon, Sep 25, 2017 at 10:12:31AM +0200, Mathieu Malaterre wrote: > Control: tags -1 pending > > Hi Salvatore, > > On Sat, Sep 23, 2017 at 1:59 PM, Salvatore Bonaccorso <car...@debian.org> > wrote: > > Source: openjpeg2 > > Version: 2.2.0-1 >

[Pkg-phototools-devel] Bug#874118: openjpeg2: CVE-2017-14039: Heap-based buffer overflow in opj_t2_encode_packet function in lib/openjp2/t2.c

2017-09-03 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: important Tags: patch upstream security Forwarded: https://github.com/uclouvain/openjpeg/issues/992 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14039[0]: | A heap-based buffer overflow was discovered in the

[Pkg-phototools-devel] Bug#874115: openjpeg2: CVE-2017-14041: Stack-based buffer over-write in pgxtoimage function in bin/jp2/convert.c

2017-09-03 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: grave Tags: upstream patch security Forwarded: https://github.com/uclouvain/openjpeg/issues/997 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14041[0]: | A stack-based buffer overflow was discovered in the pgxtoimage function

[Pkg-phototools-devel] Bug#884738: openjpeg2: CVE-2017-17480: stack-based buffer overflow in pgxtovolume function in jp3d/convert.c

2017-12-18 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-1 Severity: grave Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1044 Hi, the following vulnerability was published for openjpeg2. CVE-2017-17480[0]: | In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the |

[Pkg-phototools-devel] Bug#882032: optipng: CVE-2017-1000229: Integer Overflow Bug while parsing TIFF input file

2017-11-17 Thread Salvatore Bonaccorso
Source: optipng Version: 0.7.6-1 Severity: important Tags: security upstream Forwarded: https://sourceforge.net/p/optipng/bugs/65/ Hi, the following vulnerability was published for optipng. CVE-2017-1000229[0]: | Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 | allows an

[Pkg-phototools-devel] Bug#878839: optipng: moved to delayed/0

2017-12-08 Thread Salvatore Bonaccorso
Hi Emmanuel I perfectly realize it's not conforming to the NMU rules, so if that made you unhappy I apologies for it. I moved the optipng upload from delayed/5 to delayed/0 since was planing a security update, and the point release happening this weekend would imply stretch-version < sid-version.

[Pkg-phototools-devel] Bug#878839: optipng: diff for NMU version 0.7.6-1.1

2017-12-07 Thread Salvatore Bonaccorso
integer overflow in minitiff_read_info() (CVE-2017-1000229) +(Closes: #882032) + * gifread: Detect indirect circular dependencies in LZW tables +(CVE-2017-16938) (Closes: #878839) + + -- Salvatore Bonaccorso <car...@debian.org> Thu, 07 Dec 2017 20:43:29 +0100 + optipng (0.7.6-1) un

[Pkg-phototools-devel] Bug#888533: openjpeg2: CVE-2018-5785: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c

2018-01-27 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.3.0-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1057 Hi, the following vulnerability was published for openjpeg2. CVE-2018-5785[0]: | In OpenJPEG 2.3.0, there is an integer overflow caused by an |

[Pkg-phototools-devel] Bug#888532: openjpeg2: CVE-2018-5727: nteger overflow in opj_t1_encode_cblks in src/lib/openjp2/t1.c

2018-01-27 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.3.0-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1053 Hi, the following vulnerability was published for openjpeg2. CVE-2018-5727[0]: | In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the |

[Pkg-phototools-devel] Bug#889683: openjpeg2: CVE-2018-6616: Excessive Iteration in opj_t1_encode_cblks

2018-02-05 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.3.0-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1059 Hi, the following vulnerability was published for openjpeg2. CVE-2018-6616[0]: | In OpenJPEG 2.3.0, there is excessive iteration in the |