From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: bug#33924: OpenJPEG security issues Date: Sun, 30 Dec 2018 12:41:50 -0500 Message-ID: <20181230174150.GA21025@jasmine.lan> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="cNdxnHkX5QqsyA0e" Return-path: Received: from eggs.gnu.org ([208.118.235.92]:38777) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gdf7C-0000YH-Ea for bug-guix@gnu.org; Sun, 30 Dec 2018 12:43:07 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gdf79-0001UI-7e for bug-guix@gnu.org; Sun, 30 Dec 2018 12:43:06 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:56917) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gdf79-0001UE-4Q for bug-guix@gnu.org; Sun, 30 Dec 2018 12:43:03 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gdf77-0000Bk-Qg for bug-guix@gnu.org; Sun, 30 Dec 2018 12:43:03 -0500 Sender: "Debbugs-submit" Resent-Message-ID: Received: from eggs.gnu.org ([208.118.235.92]:38556) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gdf68-0000Vc-JT for bug-guix@gnu.org; Sun, 30 Dec 2018 12:42:01 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gdf63-0000I5-MW for bug-guix@gnu.org; Sun, 30 Dec 2018 12:42:00 -0500 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:44387) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1gdf63-0000Ex-EN for bug-guix@gnu.org; Sun, 30 Dec 2018 12:41:55 -0500 Received: from localhost (c-76-124-202-137.hsd1.pa.comcast.net [76.124.202.137]) by mail.messagingengine.com (Postfix) with ESMTPA id 55ED8E40A1 for ; Sun, 30 Dec 2018 12:41:52 -0500 (EST) Content-Disposition: inline List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: 33924@debbugs.gnu.org --cNdxnHkX5QqsyA0e Content-Type: text/plain; charset=us-ascii Content-Disposition: inline There are several open security bugs in our package of OpenJPEG 2.3.0: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=openjpeg `guix refresh -l openjpeg` reports that several thousand packages would need to be rebuilt if we changed OpenJPEG, so we will need to fix these bugs by cherry-picking the upstream bugfix patches in a grafted replacement package. If anyone is interested in doing the work and needs advice, please ask for help :) These are the CVE identifiers: CVE-2017-17479 CVE-2018-5727 CVE-2018-5785 CVE-2018-6616 CVE-2018-7648 CVE-2018-14423 CVE-2018-16375 CVE-2018-16376 CVE-2018-17480 CVE-2018-18088 --cNdxnHkX5QqsyA0e Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlwpA1oACgkQJkb6MLrK fwiX5A//TP4g8pP/049cYK6zkZlxUDIm8CrZ/7scS5w+hlWFZF1Op0bKvlLpOTKT V+JsMI1Wt7IMvMooDSAMpg6Vq+OmEYHkIBlznVmRwGIb/o9iNO0ChSlRQa778BoR bE56kXfuOovaBNgKlUUPWvDAgLxc5d5Pa1n6k93LOrUwW1hVuc4pk9z7xDoMs210 GDhU6hDL4Q2BB7z68FLpECfkX4KAQwyEEuDQDKEHfWBp93cvexqlKalRXAhVjQtq bGs/41MpWu7r06taNHVe02YUi+QiWkVSaC4qpgB7jFmVegB9besXFMcv6ifZ1GC7 iDM7H9VHAkSUUHR7lT4TXCwaCXV9hZoPRgBzqAsTsAOrEyz8IRUP4637igve5v+B y8sCbUD832BMvsSLyq3gbrpsC/AiRavKh3+nkj2p9SDa9MPaWvglvb62qlBQ/p2w WRKTpqKQoOANitBRB6T1jzqTt1ytit2MpDlouGB28vU+7It/uMpkA4Ie3DGqoOnG gKp7Srj2ZCtVUxaJMJovNz3wLi0TTHlndCu3hLQxG9hmo3srgr1lewLnSO9j3CHe Mon/CkyqYS/DTjyxqBz4gTT4gZKp6fDaPTFQLPyihYusr0je+Jysr0a8ghk4k8c6 nhirikySW4XVkHb625hKhf1rQH4m/howsL4dM/gXFx6XSeIFeYw= =41zW -----END PGP SIGNATURE----- --cNdxnHkX5QqsyA0e--