Root has patched CVE-2016-9580 in the rootio-openjpeg2 package for Root:Debian:13. Multiple fixed versions available.
{ "distro": "debian", "source": "Root", "distro_version": "13" }
1.0
"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2016-9580.json"
"root.io.4"
[ "2.5.3-2.1~deb13u1.root.io.4" ]
true
"2.5.3-2.1~deb13u1"