Package        : jasper
Version        : 1.900.1-debian1-2.4+deb8u6

The update of jasper issued as DLA-1628-1 caused a regression due to
the fix for CVE-2018-19542, a NULL pointer dereference in the function
jp2_decode, which could lead to a denial-of-service. In some cases not
only invalid jp2 files but also valid jp2 files were rejected.

For Debian 8 "Jessie", this problem has been fixed in version
1.900.1-debian1-2.4+deb8u6.

We recommend that you upgrade your jasper packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1628-2: jasper regression update

April 13, 2019
The update of jasper issued as DLA-1628-1 caused a regression due to the fix for CVE-2018-19542, a NULL pointer dereference in the function jp2_decode, which could lead to a denial...

Summary

We recommend that you upgrade your jasper packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : jasper
Version : 1.900.1-debian1-2.4+deb8u6

Related News