Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 53: openjpeg-2.3.0: 1 advisory #51100

Closed
1 task done
ckauhaus opened this issue Nov 27, 2018 · 7 comments
Closed
1 task done

Vulnerability roundup 53: openjpeg-2.3.0: 1 advisory #51100

ckauhaus opened this issue Nov 27, 2018 · 7 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Nov 27, 2018

search, files

Scanned versions: nixos-unstable: 80738ed; nixos-18.09: 5d4a1a3. May contain false positives.

@ckauhaus
Copy link
Contributor Author

ckauhaus commented Nov 27, 2018

See also #49788: CVE-2018-16376 for which no fix was available. Needs review.

@c0bw3b c0bw3b added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Nov 27, 2018
@periklis
Copy link
Contributor

For CVE-2018-18088 a possible fix is merged in openjpeg's master: uclouvain/openjpeg#1160

@periklis
Copy link
Contributor

i will create a PR for the diff

@ckauhaus
Copy link
Contributor Author

I wonder that uclouvain/openjpeg#1160 says something about CVE-2017-17480 not 18088... possible mistake?

@periklis
Copy link
Contributor

Actually it is the linked issue in NVD

@periklis
Copy link
Contributor

and it seems to solve the issue for the red null dereference in imagetopnm

@Ekleog
Copy link
Member

Ekleog commented Dec 8, 2018

This should have been fixed by #51104.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

No branches or pull requests

4 participants