[ubuntu/jammy-security] jbig2dec 0.19-3ubuntu0.1 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Tue Jul 21 17:35:48 UTC 2026
jbig2dec (0.19-3ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: OOB read in command-line tool
- debian/patches/CVE-2023-46361.patch: Avoid uninitialized allocator in
command-line tool in jbig2dec.c.
- CVE-2023-46361
* SECURITY UPDATE: DoS via integer overflow in jbig2_arith_iaid_ctx_new()
- debian/patches/CVE-2026-38076.patch: Validate SBSYMCODELEN before use
in jbig2_arith_iaid.c.
- CVE-2026-38076
Date: 2026-07-16 17:31:12.381452+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/jbig2dec/0.19-3ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list