FS#38082 - [openjpeg] security patch for multiple CVEs

Attached to Project: Arch Linux
Opened by RbN (RbN) - Monday, 09 December 2013, 19:50 GMT
Last edited by Jan de Groot (JGC) - Monday, 28 April 2014, 07:48 GMT
Task Type Bug Report
Category Upstream Bugs
Status Closed
Assigned To Jan de Groot (JGC)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

Description:
CVE-2013-6052 : heap OOB reads, information leaks
CVE-2013-6053 : heap OOB reads, information leaks
CVE-2013-6045 : heap OOB writes
CVE-2013-1447 : null pointer dereferences, division by zero, and anything that would just fit as DoS
CVE-2013-6887 : null pointer dereferences, division by zero, and anything that would just fit as DoS

[0] does not mention openjpeg 2 at all, so it is probably affected too.
These patchs will probably be reviewed and integrated upstream soon.

Patch:
[0]

Ressources:
[0] http://openwall.com/lists/oss-security/2013/12/04/6
This task depends upon

Closed by  Jan de Groot (JGC)
Monday, 28 April 2014, 07:48 GMT
Reason for closing:  Fixed
Additional comments about closing:  Upstream released 1.5.2
Comment by Sergej Pupykin (sergej) - Tuesday, 10 December 2013, 13:53 GMT
Patches cannot be applied to openjpeg2, so I'll probably wait for upstream update
Comment by Jan de Groot (JGC) - Tuesday, 11 February 2014, 15:12 GMT
Applied to openjpeg. Left out CVE2013-6045, as it causes regressions.

I wouldn't count too much on upstream making a release, probably they will come up with another version bump several months later.
Comment by RbN (RbN) - Thursday, 13 February 2014, 08:11 GMT
You consolidated 3 patch in the file openjpeg-1.5.1-CVE-2013-6045.patch.
Are they all 3 causing regressions ?

Let me know if you need help for testing.
Comment by Jan de Groot (JGC) - Friday, 14 February 2014, 12:32 GMT
Debian tracks that bug here:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734238

I used patches from Fedora, they also disable 2013-6045 because of this.

Loading...