Accepted openjpeg2 2.1.2-1.1+deb9u5 (source amd64 all) into oldstable
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 10 Jul 2020 21:04:00 +0530
Source: openjpeg2
Binary: libopenjp2-7-dev libopenjp2-7 libopenjpip7 libopenjp3d7 libopenjp2-7-dbg libopenjpip-dec-server libopenjpip-viewer libopenjpip-server libopenjp3d-tools libopenjp2-tools
Architecture: source amd64 all
Version: 2.1.2-1.1+deb9u5
Distribution: stretch-security
Urgency: high
Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
Changed-By: Utkarsh Gupta <utkarsh@debian.org>
Description:
libopenjp2-7 - JPEG 2000 image compression/decompression library
libopenjp2-7-dbg - debug symbols for libopenjp2-7, a JPEG 2000 image library
libopenjp2-7-dev - development files for OpenJPEG, a JPEG 2000 image library
libopenjp2-tools - command-line tools using the JPEG 2000 library
libopenjp3d-tools - command-line tools using the JPEG 2000 - 3D library
libopenjp3d7 - JP3D (JPEG 2000 / Part 10) image compression/decompression librar
libopenjpip-dec-server - tool to allow caching of JPEG 2000 files using JPIP protocol
libopenjpip-server - JPIP server for JPEG 2000 files
libopenjpip-viewer - JPEG 2000 java based viewer for advanced remote JPIP access
libopenjpip7 - JPEG 2000 Interactive Protocol
Closes: 931292 950000 950184
Changes:
openjpeg2 (2.1.2-1.1+deb9u5) stretch-security; urgency=high
.
* Non-maintainer upload by the LTS team.
* Fix CVE-2020-15389: opj_decompress: fix double-free
on input directory with mix of valid and invalid image.
* Fix CVE-2020-8112: opj_tcd_init_tile(): avoid integer
overflow. (Closes: #950184)
* Fix CVE-2020-6851: opj_j2k_update_image_dimensions(): reject
images whose coordinates are beyond INT_MAX. (Closes: #950000)
* Fix CVE-2019-12973: convertbmp: detect invalid file dimensions
early and bmp_read_rle4_data(): avoid potential infinite loop.
(Closes: #931292)
Checksums-Sha1:
c003f3be09cb5c2a65ff4ceb9708da5346323afc 2826 openjpeg2_2.1.2-1.1+deb9u5.dsc
c8671e7f577fdc58abde1e1f32b10d372e6f9b07 1987071 openjpeg2_2.1.2.orig.tar.gz
45f976f4dbb86e86e6cc0f0cf4ab8f7e66e50fca 28480 openjpeg2_2.1.2-1.1+deb9u5.debian.tar.xz
34b5c30e5dc54c2f6be081cf4d5781908d93d85c 1106718 libopenjp2-7-dbg_2.1.2-1.1+deb9u5_amd64.deb
37bf9f7c822d694cc7e4302230649da079c63a7e 39058 libopenjp2-7-dev_2.1.2-1.1+deb9u5_amd64.deb
4c6f7f8b8148229d4a5523bc67153a624b9b37fc 122756 libopenjp2-7_2.1.2-1.1+deb9u5_amd64.deb
cf49bebfd7a63364d0f6df6f141e586acebec39b 94898 libopenjp2-tools_2.1.2-1.1+deb9u5_amd64.deb
4373e6d53f9055a411fd6b699eeab7bb5daf0d17 42060 libopenjp3d-tools_2.1.2-1.1+deb9u5_amd64.deb
18095156d4ba7b64bed33dcceae1e0c32ba79634 85432 libopenjp3d7_2.1.2-1.1+deb9u5_amd64.deb
c5ea2567a4da4ed82427b98b36ae3a7cf8629eac 29036 libopenjpip-dec-server_2.1.2-1.1+deb9u5_amd64.deb
c8ba30f3435957ceabbf6f3d10b78880c6409736 51422 libopenjpip-server_2.1.2-1.1+deb9u5_amd64.deb
61005984a7c0df4813a6e3f1f7efa0297bb27077 45620 libopenjpip-viewer_2.1.2-1.1+deb9u5_all.deb
9e0749ac6370232dc68caf1aa0b098081c1ef1b7 61242 libopenjpip7_2.1.2-1.1+deb9u5_amd64.deb
0c0851b9b473a73ec144d57d4487754a1bdaa3c2 15630 openjpeg2_2.1.2-1.1+deb9u5_amd64.buildinfo
Checksums-Sha256:
79722e1f68fb5edac327a58a3713f120582a63053d12ba1f9b0c0db5ba3c4a12 2826 openjpeg2_2.1.2-1.1+deb9u5.dsc
4ce77b6ef538ef090d9bde1d5eeff8b3069ab56c4906f083475517c2c023dfa7 1987071 openjpeg2_2.1.2.orig.tar.gz
b02f72dab29abddeb879d8e7272e8c670aabbb8b9aecee06607b608f397e9eeb 28480 openjpeg2_2.1.2-1.1+deb9u5.debian.tar.xz
008d4e7e36e1938728f58a31fb8bf160e629d185d7db8b241c734396de41adc9 1106718 libopenjp2-7-dbg_2.1.2-1.1+deb9u5_amd64.deb
848c9feb1c6badb436a699fdb797f13dd33a56e9fb8fef30b19b3b43f73519ac 39058 libopenjp2-7-dev_2.1.2-1.1+deb9u5_amd64.deb
5153443b6003e9b355105c30c1b56c2d658abb199160f19527e3cf465f069365 122756 libopenjp2-7_2.1.2-1.1+deb9u5_amd64.deb
d9bbdbb92ac54f6776b8fb3e2122f231d00606995a47a39bd8110636d06df130 94898 libopenjp2-tools_2.1.2-1.1+deb9u5_amd64.deb
ab2f976f870d98bf621bf2f070e617cf144270b0de88edbb8cad8bb06f9a316c 42060 libopenjp3d-tools_2.1.2-1.1+deb9u5_amd64.deb
79edede8488144e7fad9c8735747229b4cddd5842223e665dfefa817de747a91 85432 libopenjp3d7_2.1.2-1.1+deb9u5_amd64.deb
ddc76f6b63c94f897cab73b0279a2fc25885c0907fb09b0557819c32e584f28c 29036 libopenjpip-dec-server_2.1.2-1.1+deb9u5_amd64.deb
a64dbc21afd08e5d060fd7da1659e35a42861b7b71f0ebe09bb66b30a8454062 51422 libopenjpip-server_2.1.2-1.1+deb9u5_amd64.deb
12c9a7b3a5db5aea73a3c4e736dbce0f6f032b4eb2a6576000dcf57dddec11c4 45620 libopenjpip-viewer_2.1.2-1.1+deb9u5_all.deb
849336b7b0d02de3dd869308507f805ff6d27de7380988834918972e2b5bda47 61242 libopenjpip7_2.1.2-1.1+deb9u5_amd64.deb
d738b5efc067bf5b5520964be8ac90fe7b5dc5b6537489cff701b74f2c8f939b 15630 openjpeg2_2.1.2-1.1+deb9u5_amd64.buildinfo
Files:
869567336a5c09f9f886a0ba57f0c892 2826 libs optional openjpeg2_2.1.2-1.1+deb9u5.dsc
40a7bfdcc66280b3c1402a0eb1a27624 1987071 libs optional openjpeg2_2.1.2.orig.tar.gz
0b17ff8b9cad59523a0a73171afca396 28480 libs optional openjpeg2_2.1.2-1.1+deb9u5.debian.tar.xz
dca2ed1feb58bd62403d2a803a1decac 1106718 debug extra libopenjp2-7-dbg_2.1.2-1.1+deb9u5_amd64.deb
99633ea0e4203a14917edd4bccb15971 39058 libdevel optional libopenjp2-7-dev_2.1.2-1.1+deb9u5_amd64.deb
8bd74af19958f9ab07e29f77c05fff15 122756 libs optional libopenjp2-7_2.1.2-1.1+deb9u5_amd64.deb
bbc9f77c054e20ad91e51a1537c39ec0 94898 graphics optional libopenjp2-tools_2.1.2-1.1+deb9u5_amd64.deb
5b1fa3ea3524a4bc9c39ea76750508a3 42060 graphics optional libopenjp3d-tools_2.1.2-1.1+deb9u5_amd64.deb
6739c24e0565900958d69dcbc065372c 85432 libs optional libopenjp3d7_2.1.2-1.1+deb9u5_amd64.deb
5adff0f92d48fcb597d5514e712d85f8 29036 graphics optional libopenjpip-dec-server_2.1.2-1.1+deb9u5_amd64.deb
44d63d6b04fc7ec261bb57f2657b585c 51422 graphics optional libopenjpip-server_2.1.2-1.1+deb9u5_amd64.deb
c80a146086575fa510c1082522551390 45620 graphics optional libopenjpip-viewer_2.1.2-1.1+deb9u5_all.deb
845542a1510b1d151b58cf8f5ba064ca 61242 libs optional libopenjpip7_2.1.2-1.1+deb9u5_amd64.deb
849d136a45f5c3155c3d3f2a3b9fb175 15630 libs optional openjpeg2_2.1.2-1.1+deb9u5_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJHBAEBCAAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl8ItG8THHV0a2Fyc2hA
ZGViaWFuLm9yZwAKCRCCPpZ2BsNLlvKnD/97eQhJUUFDBTedg+yRsck+8ZxeKM/2
MFtBb4DmSoecuoNIUpHxwkm8yl3rLsD2u+BFy9x3WzCqyyJjp5/CJpuiADq/zDYk
uI6Wz0oRdI6lqWNBAAUK7XJHXoj+ZU9T5P0ngwPYPtDynDU28YqPVYGo2THT0Kgp
Ttv/XFSZZSvy6Tk5cmJnm5RnZv7yivGAxqyCX8YMNEkm4cbeg4Mz9+wvb0lfx87Y
ZJe5WdHEd0kBqrAFCQ9tSBHbzMnVGJnC+OJDhrHBuP3EAbUDtfjpw5q28H0i+WBT
mc0fWLTNFFCk0uFNfEWeGoL9Fk82DINrNijI6pYFx3CdyWWeM23fmbPgc1ieiRWz
5N70wOmmk+iqdio8hRDj0oM36sWOAb1KzDlMY/t0s1Om7hmWf/CRae5OTbFO+gDY
DUp1l5AfkPY4O/egeQheM/oH+oXMQsY/nOQtWQL2vJz5wPfsIaOTLQIMmjcGM/+E
j9tJaoJuiwrlOKzMUFf+9xtX5rK8TZeAYrpJq0wWLJdy7Ky5c5aFDi7Ep0EUfQWH
T+EbpmaMsRmxeMpp0IooO14hh1ENBRhnt7/AFjOuIYHpQKeljCOQvW03NzNESipT
I04xG794GbWNjXwNw8E6IbpLZABr8fefEoXpUc6N4ITsvHUsi+1s8T8YQWElts5S
4nesSKq2qe4FXw==
=55vC
-----END PGP SIGNATURE-----