ALAS-2012-125


Amazon Linux AMI Security Advisory: ALAS-2012-125
Advisory Release Date: 2014-09-14 16:58 Pacific
Severity: Important

Issue Overview:

It was found that OpenJPEG failed to sanity-check an image header field before using it. A remote attacker could provide a specially-crafted image file that could cause an application linked against OpenJPEG to crash or, possibly, execute arbitrary code. (CVE-2012-3535 )


Affected Packages:

openjpeg


Issue Correction:
Run yum update openjpeg to update your system.

New Packages:
i686:
    openjpeg-devel-1.3-9.6.amzn1.i686
    openjpeg-1.3-9.6.amzn1.i686
    openjpeg-debuginfo-1.3-9.6.amzn1.i686
    openjpeg-libs-1.3-9.6.amzn1.i686

src:
    openjpeg-1.3-9.6.amzn1.src

x86_64:
    openjpeg-libs-1.3-9.6.amzn1.x86_64
    openjpeg-debuginfo-1.3-9.6.amzn1.x86_64
    openjpeg-1.3-9.6.amzn1.x86_64
    openjpeg-devel-1.3-9.6.amzn1.x86_64