MGASA-2021-0249 - Updated jasper packages fix security vulnerabilities Publication date: 13 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0249.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3443, CVE-2021-3467 A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened (CVE-2021-3443). A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened (CVE-2021-3467). References: - https://bugs.mageia.org/show_bug.cgi?id=29017 - https://lists.fedoraproject.org/archives/list/[email protected]/thread/KWAIUFNIUCGS2IMGGDTWZIUIY7BNLGKF/ - https://lists.fedoraproject.org/archives/list/[email protected]/thread/6OUXMOIV77VDB6PQ4K2ZRB44DQYYHIXW/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3443 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3467 SRPMS: - 8/core/jasper-2.0.27-1.mga8 - 8/core/mingw-jasper-2.0.27-1.mga8 - 7/core/jasper-2.0.27-1.mga7