[Git][security-tracker-team/security-tracker][master] Add CVE-2023-3932{7,8,9}/openjpeg2

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 6 08:22:54 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c5b19524 by Salvatore Bonaccorso at 2024-07-06T09:22:09+02:00
Add CVE-2023-3932{7,8,9}/openjpeg2

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,6 +3,16 @@ CVE-2024-6501
 	[bookworm] - network-manager <no-dsa> (Minor issue)
 	[bullseye] - network-manager <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2295734
+CVE-2023-39329 [Resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c]
+	- openjpeg2 <unfixed>
+	NOTE: https://github.com/uclouvain/openjpeg/issues/1474
+CVE-2023-39328 [denail of service via crafted image file]
+	- openjpeg2 <unfixed>
+	NOTE: https://github.com/uclouvain/openjpeg/issues/1471
+	NOTE: https://github.com/uclouvain/openjpeg/pull/1470
+CVE-2023-39327 [Malicious files can cause the program to enter a large loop]
+	- openjpeg2 <unfixed>
+	NOTE: https://github.com/uclouvain/openjpeg/issues/1472
 CVE-2024-6526 (A vulnerability classified as problematic has been found in CodeIgnite ...)
 	TODO: check
 CVE-2024-6525 (** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DA ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5b195249302ba7f086f699a20d3274c3f25f755

-- 
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5b195249302ba7f086f699a20d3274c3f25f755
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240706/43e18e4b/attachment.htm>


More information about the debian-security-tracker-commits mailing list