There are 3 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2023-39328:
(postponed; to be fixed through a stable update)
A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.
- CVE-2023-39329:
(postponed; to be fixed through a stable update)
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.
You can find information about how to handle these issues in the security team's documentation.
1 ignored issue:
- CVE-2019-6988:
An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.