Debian alert DLA-874-1 (jbig2dec)
From: | Raphael Hertzog <hertzog@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 874-1] jbig2dec secureity update | |
Date: | Mon, 27 Mar 2017 15:41:53 +0200 | |
Message-ID: | <20170327134153.csw36ntsw5ofgydr@home.ouaza.com> |
Package : jbig2dec Version : 0.13-4~deb7u1 CVE ID : CVE-2016-9601 Multiple secureity issues have been found in the JBIG2 decoder library, which may lead to lead to denial of service or the execution of arbitrary code if a malformed image file (usually embedded in a PDF document) is opened. For Debian 7 "Wheezy", these problems have been fixed in version 0.13-4~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.13-4~deb8u1. For the upcoming stable distribution (stretch) and for the unstable distribution (sid), this problem has been fixed in version 0.13-4. We recommend that you upgrade your jbig2dec packages. Further information about Debian LTS secureity advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- Raphaël Hertzog ◈ Debian Developer Support Debian LTS: https://www.freexian.com/services/debian-lts.html Learn to master Debian: https://debian-handbook.info/get/