MGASA-2014-0514
Dashboard / Vulnerabilities / MGASA-2014-0514
Summary: Updated jasper packages fix CVE-2014-9029
Details: Updated jasper packages fix security vulnerability: Josh Duart of the Google Security Team discovered heap-based buffer overflow flaws in JasPer, which could lead to denial of service (application crash) or the execution of arbitrary code (CVE-2014-9029).
References: https://advisories.mageia.org/MGASA-2014-0514.html, https://bugs.mageia.org/show_bug.cgi?id=14729, https://www.debian.org/security/2014/dsa-3089
Affected packages
Package
Name: jasper
Purl: pkg:rpm/mageia/jasper?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.900.1-15.1.mga4
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
