- CVE-2011-4516, CVE-2011-4517
- Two heap-based buffer overflow flaws were found in the embedded JasPer library, which is used to provide support for Part 1 of the JPEG 2000 image compression standard in the jpeg2ktopam and pamtojpeg2k tools. An attacker could create a malicious JPEG 2000 compressed image file that could cause jpeg2ktopam to crash or, potentially, execute arbitrary code with the privileges of the user running jpeg2ktopam. These flaws do not affect pamtojpeg2k.
- A stack-based buffer overflow flaw was found in the way the xpmtoppm tool processed X PixMap (XPM) image files. An attacker could create a malicious XPM file that would cause xpmtoppm to crash or, potentially, execute arbitrary code with the privileges of the user running xpmtoppm.
- Prior to this update, the pnmtofiasco and fiascotopnm utilities could not correctly read the bitfile on IBM System z and PowerPC platforms. As a consequence, images were not correctly converted. This update modifies pnmtofiasco so that the files are successfully converted.
- Prior to this update, the manual page for the pamperspective utility contained several misprints which could be confusing for users. This update corrects the misprints.
- Prior to this update, the pgmtopbm utility encountered problems when converting grayscale pgm images to black and white pbm images. As a consequence, the pgmtopbm utility generated an empty white image. This update modifies the conversion process so that the pbm image is displayed in black and white as expected.
- Prior to this update, the xwd image header contained incorrect information about the layout and the bit order when running on the rdesktop window. As a consequence, the xwdtopnm utility generated the wrong image colors. This update modifies the the xwd image header so that the correct output is displayed.
- Prior to this update, the manual pages for the pnmtojbig and pcdovtoppm utilities were missing. This update adds the missing documentation.