Debian Patches

Status for leptonlib/1.79.0-1.1+deb11u1

Patch Description Author Forwarded Bugs Origin Last update
CVE-2020-36281.patch CVE-2020-36281 heap-based buffer over-read in pixFewColorsOctcubeQuantMixed
in colorquant1.c
diff --git a/src/colorquant1.c b/src/colorquant1.c
index 52ddd38..c7a817d 100644
no
drop-imagetops Drop imagetops binary imagetops is conflicting with a netpbm binary. And it isn't very
important. So dropping it.
.
leptonlib (1.78.0-1) unstable; urgency=medium
.
* Remove /usr/bin/imagetops (closes: #926313)
Jeff Breidenbach <jab@debian.org> no debian
serial-tests Run tests serially Leptonica tests suite is not threadsafe. no
CVE-2020-36277.patch CVE-2020-36277 denial of service (application crash) via an incorrect left
shift in pixConvert2To8 in pixconv.c
===================================================================
no
CVE-2020-36278.patch CVE-2020-36278 heap-based buffer over-read in findNextBorderPixel in ccbord.c
===================================================================
no
CVE-2020-36279.patch CVE-2020-36279 heap-based buffer over-read in rasteropGeneralLow, related to
adaptmap_reg.c and adaptmap.c
diff --git a/prog/adaptmap_reg.c b/prog/adaptmap_reg.c
index 6530977..ef8dbfd 100644
no
CVE-2020-36280.patch CVE-2020-36280 heap-based buffer over-read in pixReadFromTiffStream, related
to tiffio.c
===================================================================
no
CVE-2022-38266.patch [PATCH] Issue 26393: morphapp_fuzzer: Divide-by-zero in blockconvLow * Removed the code that allowed divide by zero for tiny pix * Ditto for 4
other block convolution functions.
Dan Bloomberg <dan.bloomberg@gmail.com> no 2020-10-28

All known versions for source package 'leptonlib'

Links