Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2020-0337 Critical: Jasper DoS and Buffer Overflow Fixes

mageia
Calendar Grey August 18, 2020
Dist Mageia Esm H88
Jasper 2.0.10 security updates resolve various denial of service vulnerabilities as of August 18, 2020, impacting Mageia.
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image (CVE-2017-6851)

Summary

The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image (CVE-2017-6851).
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image (CVE-2017-6852).
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c (CVE-2017-9782).
There is a reachable assertion abort in the function jpc_dec_process_sot() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack by triggering an unexpected jpc_ppmstabtostreams return value (CVE-2017-13745).
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack (CVE-2017-13746).
There...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=27045

- - https://security.gentoo.org/glsa/201908-03

- https://www.cve.org/CVERecord?id=CVE-2017-6851

- https://www.cve.org/CVERecord?id=CVE-2017-6852

- https://www.cve.org/CVERecord?id=CVE-2017-9782

- https://www.cve.org/CVERecord?id=CVE-2017-13745

- https://www.cve.org/CVERecord?id=CVE-2017-13746

- https://www.cve.org/CVERecord?id=CVE-2017-13748

- https://www.cve.org/CVERecord?id=CVE-2017-13749

- https://www.cve.org/CVERecord?id=CVE-2017-13750

- https://www.cve.org/CVERecord?id=CVE-2017-13751

- https://www.cve.org/CVERecord?id=CVE-2017-14132

- https://www.cve.org/CVERecord?id=CVE-2018-9252

- https://www.cve.org/CVERecord?id=CVE-2018-18873

- https://www.cve.org/CVERecord?id=CVE-2018-19139

- https://www.cve.org/CVERecord?id=CVE-2018-19543

- https://www.cve.org/CVERecord?id=CVE-2018-20570

- https://www.cve.org/CVERecord?id=CVE-2018-20622

Resolution

SRPMS

- 7/core/jasper-2.0.19-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 18 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0337.html
Type: security
CVE: CVE-2017-6851, CVE-2017-6852, CVE-2017-9782, CVE-2017-13745, CVE-2017-13746, CVE-2017-13748, CVE-2017-13749, CVE-2017-13750, CVE-2017-13751, CVE-2017-14132, CVE-2018-9252, CVE-2018-18873, CVE-2018-19139, CVE-2018-19543, CVE-2018-20570, CVE-2018-20622

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here