Bug 1299772 (CVE-2016-1924)
Summary: | CVE-2016-1924 openjpeg: out of bounds read in opj_tgt_reset | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | erik-fedora, extras-orphan, hobbes1069, jaromir.capik, manisandro, nforro, oliver, phracek, rdieter, slawomir |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-09-21 00:28:39 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1299775, 1299776, 1299777, 1299778, 1377769, 1377770, 1377771, 1377772 | ||
Bug Blocks: | 1299764, 1299766 |
Description
Andrej Nemec
2016-01-19 09:32:16 UTC
Created openjpeg tracking bugs for this issue: Affects: fedora-all [bug 1299775] Affects: epel-6 [bug 1299777] Affects: epel-7 [bug 1299778] Created mingw-openjpeg tracking bugs for this issue: Affects: fedora-all [bug 1299776] The functions affected by the vulnerability do not exist in openjpeg 1.x, so this is actually NOTABUG. What is the correct way to close this bug and dependent bugs? Closing since this vulnerability does not affect openjpeg 1.x (the affected functions to not exist in openjpeg 1.x). Created mingw-openjpeg2 tracking bugs for this issue: Affects: fedora-all [bug 1377770] Created mingw-openjpeg2 tracking bugs for this issue: Affects: fedora-all [bug 1377770] Created openjpeg2 tracking bugs for this issue: Affects: fedora-all [bug 1377772] Affects: epel-all [bug 1377771] (In reply to Sandro Mani from comment #4) > Closing since this vulnerability does not affect openjpeg 1.x (the affected > functions to not exist in openjpeg 1.x). While that's true for openjpeg, we were missing openjpeg2 and mingw-openjpeg2 from the list of affected packages. Re-opening this flaw; tracking bugs for Fedora/EPEL have been filed. I am unable to reproduce the crash on current Fedora openjpeg, however discussion in the upstream patch talks about fixing integer overflow issues associated with use of opj_int_ceildiv. See also bug 1299767 (same upstream ticket) and bug 1374329 comment #14 which may be related. |