FS#43592 - [jasper] CVE-2014-8157 CVE-2014-8158: heap and stack buffer overflow
Attached to Project:
Arch Linux
Opened by Levente Polyak (anthraxx) - Tuesday, 27 January 2015, 20:19 GMT
Last edited by Eric Belanger (Snowman) - Tuesday, 27 January 2015, 21:39 GMT
Opened by Levente Polyak (anthraxx) - Tuesday, 27 January 2015, 20:19 GMT
Last edited by Eric Belanger (Snowman) - Tuesday, 27 January 2015, 21:39 GMT
|
Details
Hey,
It has been reported [0] that jasper 1.900.1-12 is vulnerable to CVE-2014-8157 [1] and CVE-2014-8158 [2] (heap and stack buffer overflow). As jasper upstream is no longer maintained I recommend to apply the attached patches from the bugzilla tracker. [0] http://seclists.org/oss-sec/2015/q1/210 [1] https://bugzilla.redhat.com/show_bug.cgi?id=1179282 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1179298 |
This task depends upon
Closed by Eric Belanger (Snowman)
Tuesday, 27 January 2015, 21:39 GMT
Reason for closing: Fixed
Additional comments about closing: jasper-1.900.1-13
Tuesday, 27 January 2015, 21:39 GMT
Reason for closing: Fixed
Additional comments about closing: jasper-1.900.1-13