Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7 MGASA-2020-0463: Critical Jasper Out-Of-Bounds Write

mageia
Calendar Grey December 17, 2020
Dist Mageia Esm H88
An issue in Jasper's encoder may jeopardize data reliability and accessibility on Mageia. Ensure you upgrade to protect your system.
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23

Summary

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability (CVE-2020-27828).

References

- https://bugs.mageia.org/show_bug.cgi?id=27842

- https://github.com/jasper-software/jasper/releases/tag/version-2.0.23

- https://www.cve.org/CVERecord?id=CVE-2020-27828

Resolution

SRPMS

- 7/core/jasper-2.0.23-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 17 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0463.html
Type: security
CVE: CVE-2020-27828

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here