jbig2dec-0.14-4.el8

エラータID: AXSA:2020-327:01

Release date: 
Thursday, September 10, 2020 - 11:10
Subject: 
jbig2dec-0.14-4.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

jbig2dec is a decoder implementation of the JBIG2 image compression format.

Security Fix(es):

* jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c (CVE-2020-12268)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-12268
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. jbig2dec-0.14-4.el8.src.rpm
    MD5: 94b19695c69de08653821c362251c64a
    SHA-256: 1aa649c1601b9c7a7da1b3545f7858c85577332a40329e3b82a884548f20fb3c
    Size: 464.86 kB

Asianux Server 8 for x86_64
  1. jbig2dec-libs-0.14-4.el8.x86_64.rpm
    MD5: 5e3bc3d1690b700b8a229f0a899e9a65
    SHA-256: 05ee9c605223a59dc0a682d0e7d7eaa29fcb3c74ede7178a23ebae887c690c60
    Size: 66.66 kB
  2. jbig2dec-libs-0.14-4.el8.i686.rpm
    MD5: 79f395a68ad8b5bdeb3dfe0e8901d63f
    SHA-256: 7e33246ac20dcdd975c1890aa1900fe37484f8f9042e64a214a947cf9e4c0ff4
    Size: 69.95 kB