|
|
Subscribe / Log in / New account

Mageia alert MGASA-2021-0249 (jasper)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2021-0249: Updated jasper packages fix security vulnerabilities
Date:  Sun, 13 Jun 2021 23:34:00 +0200
Message-ID:  <20210613213400.12A619FC65@duvel.mageia.org>
Archive-link:  Article

MGASA-2021-0249 - Updated jasper packages fix security vulnerabilities Publication date: 13 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0249.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3443, CVE-2021-3467 Description: A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened (CVE-2021-3443). A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened (CVE-2021-3467). References: - https://bugs.mageia.org/show_bug.cgi?id=29017 - https://lists.fedoraproject.org/archives/list/package-ann... - https://lists.fedoraproject.org/archives/list/package-ann... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3443 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3467 SRPMS: - 8/core/jasper-2.0.27-1.mga8 - 8/core/mingw-jasper-2.0.27-1.mga8 - 7/core/jasper-2.0.27-1.mga7


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds