ELA-394-1 leptonlib security update

heap-based buffer over-read

2021-03-31
Packageleptonlib
Version1.71-2.1+deb8u1
Related CVEs CVE-2020-36277 CVE-2020-36278 CVE-2020-36279 CVE-2020-36281

Several issues have been found in leptonlib, an image processing library.

All issues are related to heap-based buffer over-read in several functions or a denial of service (application crash) with crafted data.

For Debian 8 jessie, these problems have been fixed in version 1.71-2.1+deb8u1.

We recommend that you upgrade your leptonlib packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/