OpenJPEG: Multiple vulnerabilities Multiple vulnerabilities have been found in OpenJPEG, the worst of which could result in the arbitrary execution of code. openjpeg 2021-01-26 2021-01-26 711260 718918 remote 2.4.0 2.4.0 1.5.2-r1

OpenJPEG is an open-source JPEG 2000 library.

Multiple vulnerabilities have been discovered in OpenJPEG. Please review the CVE identifiers referenced below for details.

Please review the referenced CVE identifiers for details.

There is no known workaround at this time.

All OpenJPEG 2 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/openjpeg-2.4.0:2"

Gentoo has discontinued support OpenJPEG 1.x and any dependent packages should now be using OpenJPEG 2 or have dropped support for the library. We recommend that users unmerge OpenJPEG 1.x:

# emerge --unmerge "media-libs/openjpeg:1"
CVE-2018-21010 CVE-2019-12973 CVE-2020-15389 CVE-2020-27814 CVE-2020-27841 CVE-2020-27842 CVE-2020-27843 CVE-2020-27844 CVE-2020-27845 sam_c sam_c