Errata overview
Errata ID 647
Date 2020-03-11
Source package openjpeg2
Fixed in version 2.1.2-1.1+deb9u4
Description
This update addresses the following issues:
* Floating point exception vulnerability in openjpeg2 when processing
  untrusted images (CVE-2016-9112)
* Integer overflow in function opj_get_encoding_parameters in openjp2/pi.c
  (CVE-2018-20847)
* Heap buffer overflow in color_apply_icc_profile in bin/common/color.c
  (CVE-2018-21010)
Additional notes
CVE ID CVE-2016-9112
CVE-2018-20847
CVE-2018-21010
UCS Bug number #50918