Launchpad has imported 6 comments from the remote bug at
https://bugzilla.redhat.com/show_bug.cgi?id=835767.

If you reply to an imported comment from within Launchpad, your comment
will be sent to the remote bug automatically. Read more about
Launchpad's inter-bugtracker facilities at
https://help.launchpad.net/InterBugTracking.

------------------------------------------------------------------------
On 2012-06-27T04:51:26+00:00 Huzaifa wrote:

A heap-based buffer overflow was found in the way OpenJPEG, an open-
source JPEG 2000 codec written in C language, performed parsing of
JPEG2000 having certain number of tiles and tilesizes. A remote attacker
could provide a specially crafted JPEG 2000 file, which when opened in
an application linked against openjpeg would lead to that application
crash, or, potentially arbitrary code execution with the privileges of
the user running the application.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/comments/0

------------------------------------------------------------------------
On 2012-06-27T05:17:22+00:00 Tom wrote:

Created attachment 594684
openjpeg-tile-sanity.patch

Um, this is the relevant patch, not that one.

Reply at:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/comments/1

------------------------------------------------------------------------
On 2012-07-10T16:41:13+00:00 Vincent wrote:

This is now public:

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681075

Reply at:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/comments/2

------------------------------------------------------------------------
On 2012-07-11T03:33:44+00:00 Huzaifa wrote:

Here is the upstream commit:

http://code.google.com/p/openjpeg/source/detail?r=1727

Reply at:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/comments/3

------------------------------------------------------------------------
On 2012-07-11T03:41:00+00:00 Huzaifa wrote:

Created openjpeg tracking bugs for this issue

Affects: fedora-all [bug 839125]

Reply at:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/comments/4

------------------------------------------------------------------------
On 2012-07-11T16:42:15+00:00 errata-xmlrpc wrote:

This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1068 https://rhn.redhat.com/errata/RHSA-2012-1068.html

Reply at:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/comments/6


** Changed in: openjpeg (Fedora)
       Status: Unknown => Fix Released

** Changed in: openjpeg (Fedora)
   Importance: Unknown => High

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to openjpeg in Ubuntu.
https://bugs.launchpad.net/bugs/1023259

Title:
  (CVE-2012-3358) CVE-2012-3358 openjpeg: heap-based buffer overflow
  when processing JPEG2000 image files

Status in openjpeg package in Ubuntu:
  Fix Released
Status in openjpeg package in Debian:
  Fix Released
Status in openjpeg package in Fedora:
  Fix Released

Bug description:
  A heap-based buffer overflow was found in the way OpenJPEG, an
  open-source JPEG 2000 codec written in C language, performed parsing of
  JPEG2000 having certain number of tiles and tilesizes. A remote
  attacker could provide a specially crafted JPEG 2000 file, which when
  opened in an application linked against openjpeg would lead to that
  application crash, or, potentially arbitrary code execution with the
  privileges of the user running the application.

  Upstream patch:
  http://code.google.com/p/openjpeg/source/detail?r=1727

  References:
  https://bugzilla.redhat.com/show_bug.cgi?id=835767
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681075

  This issue has been assigned CVE-2012-3358

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/+subscriptions

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to