Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora: 2009-10737 High: jasper Remote Denial Of Service Issue

fedora
Calendar Grey October 27, 2009
Dist Fedora Esm H88
Address multiple buffer overflow vulnerabilities in Jasper 1.900.1-13 on Fedora 10 with a critical patch that enhances image processing capabilities while boosting stability and security

Summary

This package contains an implementation of the image compression

standard JPEG-2000, Part 1. It consists of tools for conversion to and

from the JP2 and JPC formats.

ChangeLog:

* Tue Oct 13 2009 Rex Dieter - 1.900.1-13

- CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls (#461476)

- CVE-2008-3522 jasper: possible buffer overflow in

jas_stream_printf() (#461478)

* Fri Jul 24 2009 Fedora Release Engineering - 1.900.1-12

- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

* Sat Jul 18 2009 Rex Dieter - 1.900.1-11

- FTBFS jasper-1.900.1-10.fc11 (#511743)

* Wed Feb 25 2009 Fedora Release Engineering - 1.900.1-10

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

References:

[ 1 ] Bug #461476 - CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls

https://bugzilla.redhat.com/show_bug.cgi?id=461476

[ 2 ] Bug #461478 - CVE-2008-3522 jasper: possible buffer overflow in jas_stream_printf()

https://bugzilla.redhat.com/show_bug.cgi?id=461478

This update can be installed with the "yum" update program. Use

su -c 'yum update jasper' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Name: jasper
Product: Fedora 10
Version: 1.900.1
Release: 13.fc10
Summary: Implementation of the JPEG-2000 standard, Part 1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here