OpenJPEG: User-assisted execution of arbitrary code Multiple vulnerabilities in OpenJPEG could result in execution of arbitrary code. openjpeg 2013-10-10 2013-10-10 412895 425772 433766 remote 1.5.1 1.5.1

OpenJPEG is an open-source JPEG 2000 library.

OpenJPEG contains an invalid free error and multiple buffer overflow flaws. Please review the CVE identifiers referenced below for details.

A remote attacker could entice a user to open a specially crafted JPEG file, possibly resulting in execution of arbitrary code or a Denial of Service condition.

There is no known workaround at this time.

All OpenJPEG users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/openjpeg-1.5.1"
CVE-2009-5030 CVE-2012-3358 CVE-2012-3535 ackle ackle