Amazon Linux 1 Security Advisory: ALAS-2012-125
Advisory Release Date: 2012-09-22 21:35 Pacific
Advisory Updated Date: 2014-09-14 16:58 Pacific
It was found that OpenJPEG failed to sanity-check an image header field before using it. A remote attacker could provide a specially-crafted image file that could cause an application linked against OpenJPEG to crash or, possibly, execute arbitrary code. (CVE-2012-3535)
Affected Packages:
openjpeg
Issue Correction:
Run yum update openjpeg to update your system.
i686:
openjpeg-devel-1.3-9.6.amzn1.i686
openjpeg-1.3-9.6.amzn1.i686
openjpeg-debuginfo-1.3-9.6.amzn1.i686
openjpeg-libs-1.3-9.6.amzn1.i686
src:
openjpeg-1.3-9.6.amzn1.src
x86_64:
openjpeg-libs-1.3-9.6.amzn1.x86_64
openjpeg-debuginfo-1.3-9.6.amzn1.x86_64
openjpeg-1.3-9.6.amzn1.x86_64
openjpeg-devel-1.3-9.6.amzn1.x86_64