Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Mageia 7 MGASA-2021-0113 Moderate: JasPer Buffer Overflow Threat

mageia
Calendar Grey March 4, 2021
Dist Mageia Esm H88
JasPer 2.0.24 exhibits several vulnerabilities that could result in data leaks and application failures. Please apply the necessary updates to resolve these problems.
jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of i...

Summary

jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components (CVE-2021-3272).
A flaw was found in jasper. An out of bounds read issue was found in jp2_decode function which may lead to disclosure of information or program crash (CVE-2021-26926).
A flaw was found in jasper. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service (CVE-2021-26927).

References

- https://bugs.mageia.org/show_bug.cgi?id=28318

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HD2Y2LT4N5ZWCMKYCUIKB3XODNJLOW3J/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ZSE7IN2V4KAQDTSMRIVDIHQ6XXFC4AUH/

- https://www.cve.org/CVERecord?id=CVE-2021-3272

- https://www.cve.org/CVERecord?id=CVE-2021-26926

- https://www.cve.org/CVERecord?id=CVE-2021-26927

Resolution

SRPMS

- 7/core/jasper-2.0.25-1.mga7

Publication date: 04 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0113.html
Type: security
CVE: CVE-2021-3272, CVE-2021-26926, CVE-2021-26927

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here