Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:2971 - Security Advisory
Issued:
2020-07-16
Updated:
2020-07-16

RHSA-2020:2971 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: jbig2dec security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for jbig2dec is now available for Red Hat Enterprise Linux 8.1 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

jbig2dec is a decoder implementation of the JBIG2 image compression format.

Security Fix(es):

  • jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c (CVE-2020-12268)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.1 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.1 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.1 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.1 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 1848518 - CVE-2020-12268 jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c

CVEs

  • CVE-2020-12268

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.1

SRPM
jbig2dec-0.14-4.el8_1.src.rpm SHA-256: 2ba60bd8296bacb900083ecd6538f720a4e293007b9fbf9d4476b8ee7d434bec
x86_64
jbig2dec-debuginfo-0.14-4.el8_1.i686.rpm SHA-256: e6577f7a2c0af0a690a7487c45805c775be504bb66ac3399720b22c010dccce6
jbig2dec-debuginfo-0.14-4.el8_1.x86_64.rpm SHA-256: c809226c3981ec2962372fe15c42d3b3d3e0e73d4d7957672f1d46983c00683d
jbig2dec-debugsource-0.14-4.el8_1.i686.rpm SHA-256: 7e3172f830e7959ddc074a08fa1e24dbb58560fdf92d35584efb8fcc6b37e26e
jbig2dec-debugsource-0.14-4.el8_1.x86_64.rpm SHA-256: 3fe29a34aeb2d1d284b4bdb543fdb101bf15313ca4e4673af5fe623c2098d85d
jbig2dec-libs-0.14-4.el8_1.i686.rpm SHA-256: b979dbb1dbb4eb44bb60cc9d3141c3cd06b98bf65e18ab80cccf74920c61e992
jbig2dec-libs-0.14-4.el8_1.x86_64.rpm SHA-256: 2fe1b940425a43c931404978ca896d463dfb70b3233e5b9da21830dcf8a87f4c
jbig2dec-libs-debuginfo-0.14-4.el8_1.i686.rpm SHA-256: b976dad0ca646c3256b05914ee8cbfec3408dd26c660bcc4b0229729c9264844
jbig2dec-libs-debuginfo-0.14-4.el8_1.x86_64.rpm SHA-256: 3e5ff0d68d3a3f0d7be55c60e05fb5628645fe7f31a49567330ac4d3320882dc

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.1

SRPM
jbig2dec-0.14-4.el8_1.src.rpm SHA-256: 2ba60bd8296bacb900083ecd6538f720a4e293007b9fbf9d4476b8ee7d434bec
s390x
jbig2dec-debuginfo-0.14-4.el8_1.s390x.rpm SHA-256: 6809e086b36a9e6d2e9b06846f523c498c94019eac9609349aa7d2b4e7f6eebd
jbig2dec-debugsource-0.14-4.el8_1.s390x.rpm SHA-256: caeb1faca4ec6ed93ddd9e13f855b01bc2776922ac90d4cf0730e463e3e2a91a
jbig2dec-libs-0.14-4.el8_1.s390x.rpm SHA-256: 10aaef42b06bfc7dfbb4266f9a10fad2f49312a6632876002c83410283169734
jbig2dec-libs-debuginfo-0.14-4.el8_1.s390x.rpm SHA-256: c64589ff79cc65f164fd86fad1eb0e3c66827f6b26adddd8ed86509e576a70bc

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.1

SRPM
jbig2dec-0.14-4.el8_1.src.rpm SHA-256: 2ba60bd8296bacb900083ecd6538f720a4e293007b9fbf9d4476b8ee7d434bec
ppc64le
jbig2dec-debuginfo-0.14-4.el8_1.ppc64le.rpm SHA-256: 92a89e33b661f3036d15b59822eb6092c95d615a764b362cd9608d68b47e3032
jbig2dec-debugsource-0.14-4.el8_1.ppc64le.rpm SHA-256: 3efee6bdde8869e9bd0c23f43d2c97ba1b78fff04b4ea526ada5cdd2cc9e71ed
jbig2dec-libs-0.14-4.el8_1.ppc64le.rpm SHA-256: 92e0323e9a979bef82b9d1a7c0be986638ad249db10002f704e0f0df0b7f4e06
jbig2dec-libs-debuginfo-0.14-4.el8_1.ppc64le.rpm SHA-256: 04754e6c15d2764fa3bc1ad115dd617a444fb3274e8806eb55967db7c0d310ab

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.1

SRPM
jbig2dec-0.14-4.el8_1.src.rpm SHA-256: 2ba60bd8296bacb900083ecd6538f720a4e293007b9fbf9d4476b8ee7d434bec
aarch64
jbig2dec-debuginfo-0.14-4.el8_1.aarch64.rpm SHA-256: 7c3ff2fd21a5d3865b337fe0bbdb85785ae20c21eecef4b6f19132252bef732c
jbig2dec-debugsource-0.14-4.el8_1.aarch64.rpm SHA-256: 26dc4617e63d28acad4278ab7ad19c9834b52227d204d8f43b5f6165f3a7ac67
jbig2dec-libs-0.14-4.el8_1.aarch64.rpm SHA-256: 833f774bdeea5779b6eb79ae104c1b15c67ec4f675ffc6a3402298b6b943da50
jbig2dec-libs-debuginfo-0.14-4.el8_1.aarch64.rpm SHA-256: 0f5fd7083f4a4bf683420b77b2dac6df06ffa20b3fcb40b712e1fbad595d77ab

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
jbig2dec-0.14-4.el8_1.src.rpm SHA-256: 2ba60bd8296bacb900083ecd6538f720a4e293007b9fbf9d4476b8ee7d434bec
ppc64le
jbig2dec-debuginfo-0.14-4.el8_1.ppc64le.rpm SHA-256: 92a89e33b661f3036d15b59822eb6092c95d615a764b362cd9608d68b47e3032
jbig2dec-debugsource-0.14-4.el8_1.ppc64le.rpm SHA-256: 3efee6bdde8869e9bd0c23f43d2c97ba1b78fff04b4ea526ada5cdd2cc9e71ed
jbig2dec-libs-0.14-4.el8_1.ppc64le.rpm SHA-256: 92e0323e9a979bef82b9d1a7c0be986638ad249db10002f704e0f0df0b7f4e06
jbig2dec-libs-debuginfo-0.14-4.el8_1.ppc64le.rpm SHA-256: 04754e6c15d2764fa3bc1ad115dd617a444fb3274e8806eb55967db7c0d310ab

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
jbig2dec-0.14-4.el8_1.src.rpm SHA-256: 2ba60bd8296bacb900083ecd6538f720a4e293007b9fbf9d4476b8ee7d434bec
x86_64
jbig2dec-debuginfo-0.14-4.el8_1.i686.rpm SHA-256: e6577f7a2c0af0a690a7487c45805c775be504bb66ac3399720b22c010dccce6
jbig2dec-debuginfo-0.14-4.el8_1.x86_64.rpm SHA-256: c809226c3981ec2962372fe15c42d3b3d3e0e73d4d7957672f1d46983c00683d
jbig2dec-debugsource-0.14-4.el8_1.i686.rpm SHA-256: 7e3172f830e7959ddc074a08fa1e24dbb58560fdf92d35584efb8fcc6b37e26e
jbig2dec-debugsource-0.14-4.el8_1.x86_64.rpm SHA-256: 3fe29a34aeb2d1d284b4bdb543fdb101bf15313ca4e4673af5fe623c2098d85d
jbig2dec-libs-0.14-4.el8_1.i686.rpm SHA-256: b979dbb1dbb4eb44bb60cc9d3141c3cd06b98bf65e18ab80cccf74920c61e992
jbig2dec-libs-0.14-4.el8_1.x86_64.rpm SHA-256: 2fe1b940425a43c931404978ca896d463dfb70b3233e5b9da21830dcf8a87f4c
jbig2dec-libs-debuginfo-0.14-4.el8_1.i686.rpm SHA-256: b976dad0ca646c3256b05914ee8cbfec3408dd26c660bcc4b0229729c9264844
jbig2dec-libs-debuginfo-0.14-4.el8_1.x86_64.rpm SHA-256: 3e5ff0d68d3a3f0d7be55c60e05fb5628645fe7f31a49567330ac4d3320882dc

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility