MGASA-2018-0281
Dashboard / Vulnerabilities / MGASA-2018-0281
Summary: Updated jasper packages fix security vulnerabilities
Details: Updated japser packages fix security vulnerabilities: An assertion failure was possible to trigger in JPC_NOMINALGAIN (CVE-2016-9396). Denial of service via a reachable assertion in the function jpc_firstone in libjasper/jpc/jpc_math.c could lead to denial of service (CVE-2018-9055).
References: https://advisories.mageia.org/MGASA-2018-0281.html, https://bugs.mageia.org/show_bug.cgi?id=23139, https://blogs.gentoo.org/ago/2016/11/16/jasper-multiple-assertion-failure/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/V63HVBFSQBPI6D3JW46NY32DKGCE2YB4/, https://lists.opensuse.org/opensuse-updates/2018-05/msg00130.html
Affected packages
Package
Name: jasper
Purl: pkg:rpm/mageia/jasper?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
