| Summary: | openjpeg new security issue CVE-2012-3535 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | critical | ||
| Priority: | Normal | CC: | ed_rus099, sysadmin-bugs, tmb |
| Version: | 2 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/516634/ | ||
| Whiteboard: | MGA1TOO has_procedure mga1-32-OK mga1-64-OK mga2-32-OK mga2-64-OK | ||
| Source RPM: | openjpeg | CVE: | |
| Status comment: | |||
|
Description
David Walser
2012-09-17 22:17:46 CEST
David Walser
2012-09-17 22:17:54 CEST
Whiteboard:
(none) =>
MGA1TOO Tested on Mageia 2 x86_64. Here is the testing procedure used for this package: http://www.openjpeg.org/index.php?menu=samples I don't know if this is the right way to test this package. CC:
(none) =>
ed_rus099 I forgot to say that works ok. :) Yes that works Eduard, well done for finding it. It's an open source jpeg2000 library. From memory, I don't think mga1 has the image_to_j2k command. I think we used Krita last time for that
claire robinson
2012-09-18 09:42:18 CEST
Hardware:
i586 =>
All Testing complete Mga1 32
Tested using krita to open a j2k and then open a bmp and save as jpeg2000
$ grep libopenjpeg strace.out | grep -v "such file"
open("/usr/lib/libopenjpeg.so.2", O_RDONLY) = 26
claire robinson
2012-09-18 10:51:49 CEST
Whiteboard:
MGA1TOO has_procedure mga2-64-OK =>
MGA1TOO has_procedure mga1-32-OK mga2-64-OK Testing complete mga1 64
$ grep libopenjpeg strace.out | grep -v "such file"
open("/usr/lib64/libopenjpeg.so.2", O_RDONLY) = 28Whiteboard:
MGA1TOO has_procedure mga1-32-OK mga2-64-OK =>
MGA1TOO has_procedure mga1-32-OK mga1-64-OK mga2-64-OK Testing complete mga2 32 Validating See comment 0 for advisory and srpms Could sysadmin please push from core/updates_testing to core/updates Thanks! Keywords:
(none) =>
validated_update Update pushed: https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0274 Status:
NEW =>
RESOLVED |