MGASA-2014-0539
Dashboard / Vulnerabilities / MGASA-2014-0539
Summary: Updated jasper packages fix security vulnerabilities
Details: Updated jasper packages fix security vulnerabilities: A double free flaw was found in the way JasPer parsed ICC color profiles in JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code (CVE-2014-8137). A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code (CVE-2014-8138).
References: https://advisories.mageia.org/MGASA-2014-0539.html, https://bugs.mageia.org/show_bug.cgi?id=14845, http://www.ocert.org/advisories/ocert-2014-012.html
Affected packages
Package
Name: jasper
Purl: pkg:rpm/mageia/jasper?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
