[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: v2: OpenJPEG security fixes (CVE-2016-{5157,7163})
From: |
Leo Famulari |
Subject: |
Re: v2: OpenJPEG security fixes (CVE-2016-{5157,7163}) |
Date: |
Fri, 9 Sep 2016 16:26:39 -0400 |
User-agent: |
Mutt/1.7.0 (2016-08-17) |
On Fri, Sep 09, 2016 at 02:04:58PM -0400, Leo Famulari wrote:
> Also, the fix for CVE-2016-5157 does not apply to openjpeg-2.0. I'd like
> to investigate this issue separately. The only user of openjpeg-2.0 is
> mupdf.
I think the best thing to do is update mupdf to the latest upstream
release, 1.9a, make it use address@hidden, and remove openjpeg-2.0.
Please see attached. These patches should be applied on top of the
patches in the email that I am replying to.
0001-gnu-mupdf-Update-to-1.9a.patch
Description: Text document
0002-gnu-Remove-openjpeg-2.0.patch
Description: Text document
signature.asc
Description: PGP signature
- [PATCH 0/2] OpenJPEG security fixes (CVE-2016-{5157,7163}), Leo Famulari, 2016/09/09
- [PATCH 2/2] gnu: openjpeg-2.*: Fix CVE-2016-5157., Leo Famulari, 2016/09/09
- Re: [PATCH 0/2] OpenJPEG security fixes (CVE-2016-{5157,7163}), Efraim Flashner, 2016/09/09
- v2: OpenJPEG security fixes (CVE-2016-{5157,7163}), Leo Famulari, 2016/09/09
- Re: v2: OpenJPEG security fixes (CVE-2016-{5157,7163}),
Leo Famulari <=