-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 19 Nov 2018 17:23:30 +0100 Source: openjpeg2 Binary: libopenjp2-7-dev libopenjp2-7 libopenjpip7 libopenjp3d7 libopenjp2-7-dbg libopenjpip-dec-server libopenjpip-viewer libopenjpip-server libopenjp3d-tools libopenjp2-tools Architecture: source amd64 all Version: 2.1.0-2+deb8u5 Distribution: jessie-security Urgency: high Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org> Changed-By: Hugo Lefeuvre <hle@debian.org> Description: libopenjp2-7 - JPEG 2000 image compression/decompression library libopenjp2-7-dbg - debug symbols for libopenjp2-7, a JPEG 2000 image library libopenjp2-7-dev - development files for OpenJPEG, a JPEG 2000 image library libopenjp2-tools - command-line tools using the JPEG 2000 library libopenjp3d-tools - command-line tools using the JPEG 2000 - 3D library libopenjp3d7 - JP3D (JPEG 2000 / Part 10) image compression/decompression librar libopenjpip-dec-server - tool to allow caching of JPEG 2000 files using JPIP protocol libopenjpip-server - JPIP server for JPEG 2000 files libopenjpip-viewer - JPEG 2000 java based viewer for advanced remote JPIP access libopenjpip7 - JPEG 2000 Interactive Protocol Changes: openjpeg2 (2.1.0-2+deb8u5) jessie-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2017-17480: write stack buffer overflow due to missing buffer length formatter in fscanf call. * CVE-2018-18088: null pointer dereference caused by null image components in imagetopnm. Checksums-Sha1: 8e6a073a44cd8d6d835597f1cd47d5b2e981a10e 2420 openjpeg2_2.1.0-2+deb8u5.dsc d2b2e1f8aa6d1452f092476bb19bdf8715830289 29512 openjpeg2_2.1.0-2+deb8u5.debian.tar.xz efca96fca1b71e6d8a0fd54d0262c313d0707a18 38882 libopenjp2-7-dev_2.1.0-2+deb8u5_amd64.deb 8147a70b89701faafabeaa6685cf42da0df20628 117602 libopenjp2-7_2.1.0-2+deb8u5_amd64.deb 76a111d8275a1ad9207b17b6d599b8f6f2e5999b 60782 libopenjpip7_2.1.0-2+deb8u5_amd64.deb f9d2f3e1a7842b92f28ce96c7d313dcf9ef2b127 85524 libopenjp3d7_2.1.0-2+deb8u5_amd64.deb f67953cd0739bea52e8e631fa555ba9f6be286ce 918030 libopenjp2-7-dbg_2.1.0-2+deb8u5_amd64.deb ff5e91cf3b7c5bca659aca2023c493f873565f79 28792 libopenjpip-dec-server_2.1.0-2+deb8u5_amd64.deb 49801a70cdb791cbb686905c3c6bb901b11dcc2a 45538 libopenjpip-viewer_2.1.0-2+deb8u5_all.deb ada369afb2f32abe769a6e4481118c888d2be3af 49506 libopenjpip-server_2.1.0-2+deb8u5_amd64.deb b5339486e69a0d564efec2ca11ec4229b1ee02ef 41406 libopenjp3d-tools_2.1.0-2+deb8u5_amd64.deb 2294d8035ac1a0947da0d1e45ba17e082cb697ea 79116 libopenjp2-tools_2.1.0-2+deb8u5_amd64.deb Checksums-Sha256: 91a711b2d01eab45041d7fd9a9d9e1120a5e9c360db8c0a0322a22fbbd872242 2420 openjpeg2_2.1.0-2+deb8u5.dsc f4a97964416b6ae34bfbf38b61ed9620d8c1e9bc3ee8784f78ccf564d1accb2d 29512 openjpeg2_2.1.0-2+deb8u5.debian.tar.xz 6fd7d010aff79e600aff0de2902edb00bd22f094c7a7827e84cee78cea3e75c8 38882 libopenjp2-7-dev_2.1.0-2+deb8u5_amd64.deb f4c57c887ca514af49d94643e8c43d9328b6288ef6ec0f562ff0ebb66268122e 117602 libopenjp2-7_2.1.0-2+deb8u5_amd64.deb bf5d4337f8ef4967ac608adeb54e83e9ef4c43e3cba0c4db06779d3c54ae5231 60782 libopenjpip7_2.1.0-2+deb8u5_amd64.deb a6927246bf70b1a98bd6054083a50843f6bdb3349516591230ad18511e917043 85524 libopenjp3d7_2.1.0-2+deb8u5_amd64.deb 47f4dedd7baacbeed0ab9aab1d9e51abaa66676f89ad763da0ccb7048573bb40 918030 libopenjp2-7-dbg_2.1.0-2+deb8u5_amd64.deb b80f0ff4aac4b3376a543ce58dd1d0640ddca6fb6456dad607d00d9e4e4f5ec4 28792 libopenjpip-dec-server_2.1.0-2+deb8u5_amd64.deb c5faea7d26f93b3f1fde0a69367a9b49d5902d25b28fc51ed829892854413af5 45538 libopenjpip-viewer_2.1.0-2+deb8u5_all.deb f5cb922bfa897101aae4ad916c369ad1314a91e819ea9962596e7f68e8203d09 49506 libopenjpip-server_2.1.0-2+deb8u5_amd64.deb dcca7ab36ecf87b1b2c578f674e6319ab7dd14ec065e0b7c4568f6ee29855b84 41406 libopenjp3d-tools_2.1.0-2+deb8u5_amd64.deb 5a5d168194f3319b89e8f9c3ecd66c076bd02f9e7d522da07c6ae98d12876d0e 79116 libopenjp2-tools_2.1.0-2+deb8u5_amd64.deb Files: e1028feb7c357c99e7efb2636a79730d 2420 libs extra openjpeg2_2.1.0-2+deb8u5.dsc 38e87e171c9fb5cc9720d06b88b5f8fc 29512 libs extra openjpeg2_2.1.0-2+deb8u5.debian.tar.xz 678ab30171140b53a524e53e2c7a828f 38882 libdevel extra libopenjp2-7-dev_2.1.0-2+deb8u5_amd64.deb 362e9b94836c78859be9f3d80568b140 117602 libs extra libopenjp2-7_2.1.0-2+deb8u5_amd64.deb b4a58a015abea9a174161d114afa230e 60782 libs extra libopenjpip7_2.1.0-2+deb8u5_amd64.deb 761199320d4ead48cd146e9433dadb52 85524 libs extra libopenjp3d7_2.1.0-2+deb8u5_amd64.deb 580f878fd366cf14f6d717a7a7ddc8b3 918030 debug extra libopenjp2-7-dbg_2.1.0-2+deb8u5_amd64.deb 4b4558bd4becbf7dc265d3ad0eb061e2 28792 graphics extra libopenjpip-dec-server_2.1.0-2+deb8u5_amd64.deb d09ad64ee14a3d9fb110f798b2c6d8c5 45538 graphics extra libopenjpip-viewer_2.1.0-2+deb8u5_all.deb 54df479fbb0194d103edbf005bfa5c9d 49506 graphics extra libopenjpip-server_2.1.0-2+deb8u5_amd64.deb a3aedbee8988322b3107b093e3db2265 41406 graphics extra libopenjp3d-tools_2.1.0-2+deb8u5_amd64.deb 8ee847bdc8969c3efed16843a9f384bb 79116 graphics extra libopenjp2-tools_2.1.0-2+deb8u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEUFZhdgIWqBhwqCvuZYVUZx9w0DQFAlvy8R4ACgkQZYVUZx9w 0DTv3Af+I3N71xG6JDctYa0nyXcv7BqyVdz1bB9+XqTNEAHx3nQJibnNzdl5wghF vfCePojKDvXgjTjJxGPd142qh9XN1CPuAzH6bmNSAtVcl+NFUbM8rBy6/F3tvnWg OKXO4xr+3rFUJ6CfSuEbBU6U14ya192oSx8CYQZ3pMR4HUWwmSN4Iru5Cf+mrqRx aZ5EZ7zPVE/1IX2hvYoffI//b7L+KIBScJc/3Na0dAWG9Jb2Ml7cASR2UypursPQ 9ftxHuT1lNdUvoHWch/iX+oMCMaLxBgjdzSSjL1H+q2H4I6RYYCRrW21DeiLGUfk sa6jA11eRa0PLx59DWDkQlpfFJElNg== =r1pJ -----END PGP SIGNATURE-----