FS#68889 - [jasper] [Security] arbitrary code execution (CVE-2020-27828)
Attached to Project:
Arch Linux
Opened by Jonas Witschel (diabonas) - Tuesday, 08 December 2020, 09:12 GMT
Last edited by Levente Polyak (anthraxx) - Wednesday, 13 January 2021, 23:54 GMT
Opened by Jonas Witschel (diabonas) - Tuesday, 08 December 2020, 09:12 GMT
Last edited by Levente Polyak (anthraxx) - Wednesday, 13 January 2021, 23:54 GMT
|
Details
Summary
======= The package jasper is vulnerable to arbitrary code execution via CVE-2020-27828. Guidance ======== Updating to the freshly released version 2.0.23 fixes the issue, see https://github.com/jasper-software/jasper/releases/tag/version-2.0.23 References ========== https://security.archlinux.org/AVG-1331 https://github.com/jasper-software/jasper/issues/252 https://github.com/jasper-software/jasper/pull/253 https://github.com/jasper-software/jasper/commit/a1f26d21aa1484f811de7cd64d1565334a655449 |
This task depends upon
Closed by Levente Polyak (anthraxx)
Wednesday, 13 January 2021, 23:54 GMT
Reason for closing: Fixed
Additional comments about closing: 2.0.24-1
Wednesday, 13 January 2021, 23:54 GMT
Reason for closing: Fixed
Additional comments about closing: 2.0.24-1