Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 63: openjpeg-2.3.0: 8 advisories #57180

Closed
7 of 8 tasks
ckauhaus opened this issue Mar 9, 2019 · 7 comments
Closed
7 of 8 tasks

Vulnerability roundup 63: openjpeg-2.3.0: 8 advisories #57180

ckauhaus opened this issue Mar 9, 2019 · 7 comments

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Mar 9, 2019

search, files

Scanned versions: nixos-19.03: 5847485. May contain false positives.

@ckauhaus
Copy link
Contributor Author

ckauhaus commented Mar 9, 2019

See also #55389

@danderson
Copy link
Contributor

What a bounty of CVEs!

There is a 2.3.1 patch release that seems to include most of these:

uclouvain/openjpeg#1044 , in 2.3.1.

uclouvain/openjpeg#1123 , in 2.3.1.

uclouvain/openjpeg#1126 , in 2.3.1.

uclouvain/openjpeg#1127 , not fixed upstream.

uclouvain/openjpeg#1053 , in 2.3.1.

uclouvain/openjpeg#1057 , in 2.3.1.

uclouvain/openjpeg#1059 , in 2.3.1.

uclouvain/openjpeg#1178 , not fixed upstream.

So, upgrading to 2.3.1 will fix all the CVEs that are fixed upstream... But it still leaves 2 unfixed CVEs. Unfortunately openjpeg is a widely used package, marking it insecure would break a large package closure.

I will send a PR to upgrade to 2.3.1 at least, but we need to decide what to do about the unfixed CVEs.

@danderson
Copy link
Contributor

My mistake, unstable + 19.09 + 20.03 are already on 2.3.1. So most of these are patched, and we're as patched as we can be given the status of upstream.

@andir
Copy link
Member

andir commented Mar 13, 2020

@danderson I marked all but CVE-2019-6988 as solved in the initial post. That seems like the correct state. Do you agree?

@danderson
Copy link
Contributor

@andir CVE-2018-16376 is also not patched right now (no upstream patch).

@ckauhaus
Copy link
Contributor Author

Asked upstream

@rnhmjoj
Copy link
Contributor

rnhmjoj commented Jul 15, 2020

Closing as Nixos 19.03 is no longer supported.

@rnhmjoj rnhmjoj closed this as completed Jul 15, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants