ALAS-2023-451


Amazon Linux 2023 Security Advisory: ALAS-2023-451
Advisory Release Date: 2023-12-06 07:45 Pacific
Advisory Updated Date: 2023-12-14 21:42 Pacific
Severity: Medium

Issue Overview:

Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. (CVE-2023-46361)


Affected Packages:

jbig2dec


Issue Correction:
Run dnf update jbig2dec --releasever 2023.3.20231211 to update your system.

New Packages:
aarch64:
    jbig2dec-debuginfo-0.19-4.amzn2023.0.2.aarch64
    jbig2dec-debugsource-0.19-4.amzn2023.0.2.aarch64
    jbig2dec-libs-0.19-4.amzn2023.0.2.aarch64
    jbig2dec-0.19-4.amzn2023.0.2.aarch64
    jbig2dec-libs-debuginfo-0.19-4.amzn2023.0.2.aarch64
    jbig2dec-devel-0.19-4.amzn2023.0.2.aarch64

src:
    jbig2dec-0.19-4.amzn2023.0.2.src

x86_64:
    jbig2dec-debugsource-0.19-4.amzn2023.0.2.x86_64
    jbig2dec-libs-0.19-4.amzn2023.0.2.x86_64
    jbig2dec-devel-0.19-4.amzn2023.0.2.x86_64
    jbig2dec-libs-debuginfo-0.19-4.amzn2023.0.2.x86_64
    jbig2dec-debuginfo-0.19-4.amzn2023.0.2.x86_64
    jbig2dec-0.19-4.amzn2023.0.2.x86_64