Debian Package Tracker
Register | Log in
Subscribe

openjpeg2

Choose email to subscribe with

general
  • source: openjpeg2 (main)
  • version: 2.5.0-1
  • maintainer: Debian PhotoTools Maintainers (archive) (DMD)
  • uploaders: Hugo Lefeuvre [DMD] – Mathieu Malaterre [DMD]
  • arch: all any
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.1.2-1.1+deb9u4
  • o-o-sec: 2.1.2-1.1+deb9u7
  • oldstable: 2.3.0-2+deb10u2
  • old-sec: 2.3.0-2+deb10u2
  • stable: 2.4.0-3
  • testing: 2.5.0-1
  • unstable: 2.5.0-1
versioned links
  • 2.1.2-1.1+deb9u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.2-1.1+deb9u7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.3.0-2+deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.0-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.5.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libopenjp2-7
  • libopenjp2-7-dev
  • libopenjp2-tools (1 bugs: 0, 0, 1, 0)
  • libopenjpip-dec-server
  • libopenjpip-server
  • libopenjpip-viewer
  • libopenjpip7
  • openjpeg-doc
action needed
2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:
  • CVE-2019-6988: An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.
  • CVE-2021-3575: A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
Created: 2022-07-04 Last update: 2023-03-27 11:06
lintian reports 81 warnings high
Lintian reports 81 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2021-04-11 Last update: 2023-02-04 00:04
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2022-07-27 Last update: 2023-03-28 23:04
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • libopenjpip-viewer could be marked Multi-Arch: foreign
Created: 2020-02-11 Last update: 2023-03-28 20:10
4 low-priority security issues in bullseye low

There are 4 open security issues in bullseye.

3 issues left for the package maintainer to handle:
  • CVE-2021-3575: (needs triaging) A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
  • CVE-2022-1122: (needs triaging) A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
  • CVE-2021-29338: (needs triaging) Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

You can find information about how to handle these issues in the security team's documentation.

1 ignored issue:
  • CVE-2019-6988: An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.
Created: 2022-07-04 Last update: 2023-03-27 11:06
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 2.5.0-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
Build log checks report 1 warning low
Build log checks report 1 warning
Created: 2019-03-11 Last update: 2019-03-11 15:23
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-12-17 Last update: 2022-12-17 19:17
news
[rss feed]
  • [2022-06-26] openjpeg2 2.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-06-20] Accepted openjpeg2 2.5.0-1 (source) into unstable (Mathieu Malaterre)
  • [2022-04-10] Accepted openjpeg2 2.1.2-1.1+deb9u7 (source) into oldoldstable (Anton Gladky)
  • [2022-01-22] openjpeg2 2.4.0-6 MIGRATED to testing (Debian testing watch)
  • [2022-01-17] Accepted openjpeg2 2.4.0-6 (source) into unstable (Mathieu Malaterre)
  • [2022-01-14] Accepted openjpeg2 2.4.0-5 (source) into unstable (Mathieu Malaterre)
  • [2022-01-14] Accepted openjpeg2 2.4.0-4 (source amd64 all) into unstable, unstable (Debian FTP Masters) (signed by: Mathieu Malaterre)
  • [2021-04-05] Accepted openjpeg2 2.3.0-2+deb10u2 (source amd64 all) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2021-04-01] Accepted openjpeg2 2.3.0-2+deb10u2 (source amd64 all) into stable->embargoed, stable (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2021-02-20] openjpeg2 2.4.0-3 MIGRATED to testing (Debian testing watch)
  • [2021-02-09] Accepted openjpeg2 2.4.0-3 (source) into unstable (Mathieu Malaterre)
  • [2021-02-08] Accepted openjpeg2 2.1.2-1.1+deb9u6 (source amd64 all) into oldstable (Brian May)
  • [2021-02-08] Accepted openjpeg2 2.4.0-2 (source) into unstable (Mathieu Malaterre)
  • [2021-02-02] openjpeg2 2.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-27] Accepted openjpeg2 2.4.0-1 (source) into unstable (Mathieu Malaterre)
  • [2020-07-10] Accepted openjpeg2 2.1.2-1.1+deb9u5 (source amd64 all) into oldstable (Utkarsh Gupta)
  • [2020-01-30] Accepted openjpeg2 2.1.0-2+deb8u10 (source amd64 all) into oldoldstable (Mike Gabriel)
  • [2020-01-28] Accepted openjpeg2 2.1.0-2+deb8u9 (source amd64 all) into oldoldstable (Mike Gabriel)
  • [2019-12-29] Accepted openjpeg2 2.3.0-2+deb10u1 (source amd64 all) into proposed-updates->stable-new, proposed-updates (Hugo Lefeuvre)
  • [2019-10-29] Accepted openjpeg2 2.1.2-1.1+deb9u4 (source amd64 all) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Hugo Lefeuvre)
  • [2019-10-13] openjpeg2 2.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2019-10-08] Accepted openjpeg2 2.1.0-2+deb8u8 (source amd64 all) into oldoldstable (Hugo Lefeuvre)
  • [2019-10-08] Accepted openjpeg2 2.3.1-1 (source) into unstable (Hugo Lefeuvre)
  • [2019-10-05] openjpeg2 2.3.0-3 MIGRATED to testing (Debian testing watch)
  • [2019-09-30] Accepted openjpeg2 2.3.0-3 (source) into unstable (Mathieu Malaterre)
  • [2019-07-10] Accepted openjpeg2 2.1.0-2+deb8u7 (source amd64 all) into oldoldstable (Markus Koschany)
  • [2019-03-15] openjpeg2 2.3.0-2 MIGRATED to testing (Debian testing watch)
  • [2019-03-12] Accepted openjpeg2 2.1.2-1.1+deb9u3 (source amd64 all) into proposed-updates->stable-new, proposed-updates (Luciano Bello)
  • [2019-03-10] Accepted openjpeg2 2.3.0-2 (source) into unstable (Mathieu Malaterre)
  • [2019-03-10] Accepted openjpeg2 2.1.2-1.1+deb9u3 (source amd64 all) into stable->embargoed, stable (Luciano Bello)
  • 1
  • 2
bugs [bug history graph]
  • all: 4
  • RC: 0
  • I&N: 3
  • M&W: 1
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 81)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.5.0-1build1
  • 2 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing