Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora: 2009:10761 Critical: Overflow Issues in Jasper Image Library

fedora
Calendar Grey October 27, 2009
Dist Fedora Esm H88
Critical patches for Fedora 11 addressing integer and buffer overflow vulnerabilities in jasper enhance safety in graphic handling.

Summary

This package contains an implementation of the image compression

standard JPEG-2000, Part 1. It consists of tools for conversion to and

from the JP2 and JPC formats.

ChangeLog:

* Tue Oct 13 2009 Rex Dieter - 1.900.1-13

- CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls (#461476)

- CVE-2008-3522 jasper: possible buffer overflow in

jas_stream_printf() (#461478)

* Fri Jul 24 2009 Fedora Release Engineering - 1.900.1-12

- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

* Sat Jul 18 2009 Rex Dieter - 1.900.1-11

- FTBFS jasper-1.900.1-10.fc11 (#511743)

References:

[ 1 ] Bug #461476 - CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls

https://bugzilla.redhat.com/show_bug.cgi?id=461476

[ 2 ] Bug #461478 - CVE-2008-3522 jasper: possible buffer overflow in jas_stream_printf()

https://bugzilla.redhat.com/show_bug.cgi?id=461478

This update can be installed with the "yum" update program. Use

su -c 'yum update jasper' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: jasper
Product: Fedora 11
Version: 1.900.1
Release: 13.fc11
Summary: Implementation of the JPEG-2000 standard, Part 1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here