Comment 64 for bug 711061

Revision history for this message
Michael Catanzaro (mike-catanzaro) wrote :

The security review in comment #59 and comment #60 looks very nice. I skimmed over the issues and noticed that almost all of them affect the utility tools (in bin), not the library itself. You may or may not consider that relevant to the MIR. The issues affecting the library code are:

https://github.com/uclouvain/openjpeg/issues/719
https://github.com/uclouvain/openjpeg/issues/1071
https://github.com/uclouvain/openjpeg/issues/1076
https://github.com/uclouvain/openjpeg/issues/1077
https://github.com/uclouvain/openjpeg/issues/1078

There's also issue 1073, but that issue is disputed by upstream and doesn't affect Ubuntu anyway because Ubuntu uses system libtiff instead of the bundled code. All the other issues are in bin.