Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
JasPer is an implementation of Part 1 of the JPEG 2000 image compression
standard.
Security Fix(es):
Multiple flaws were found in the way JasPer decoded JPEG 2000 image files.
A specially crafted file could cause an application using JasPer to crash
or, possibly, execute arbitrary code. (CVE-2016-8654, CVE-2016-9560,
CVE-2016-10249, CVE-2015-5203, CVE-2015-5221, CVE-2016-1577, CVE-2016-8690,
CVE-2016-8693, CVE-2016-8884, CVE-2016-8885, CVE-2016-9262, CVE-2016-9591)
Multiple flaws were found in the way JasPer decoded JPEG 2000 image files.
A specially crafted file could cause an application using JasPer to crash.
(CVE-2016-1867, CVE-2016-2089, CVE-2016-2116, CVE-2016-8691, CVE-2016-8692,
CVE-2016-8883, CVE-2016-9387, CVE-2016-9388, CVE-2016-9389, CVE-2016-9390,
CVE-2016-9391, CVE-2016-9392, CVE-2016-9393, CVE-2016-9394, CVE-2016-9583,
CVE-2016-9600, CVE-2016-10248, CVE-2016-10251)
Red Hat would like to thank Liu Bingchang (IIE) for reporting
CVE-2016-8654, CVE-2016-9583, CVE-2016-9591, and CVE-2016-9600; Gustavo
Grieco for reporting CVE-2015-5203; and Josselin Feist for reporting
CVE-2015-5221.
https://access.redhat.com/security/cve/CVE-2015-5203 https://access.redhat.com/security/cve/CVE-2015-5221 https://access.redhat.com/security/cve/CVE-2016-10248 https://access.redhat.com/security/cve/CVE-2016-10249 https://access.redhat.com/security/cve/CVE-2016-10251 https://access.redhat.com/security/cve/CVE-2016-1577 https://access.redhat.com/security/cve/CVE-2016-1867 https://access.redhat.com/security/cve/CVE-2016-2089 https://access.redhat.com/security/cve/CVE-2016-2116 https://access.redhat.com/security/cve/CVE-2016-8654 https://access.redhat.com/security/cve/CVE-2016-8690 https://access.redhat.com/security/cve/CVE-2016-8691 https://access.redhat.com/security/cve/CVE-2016-8692 https://access.redhat.com/security/cve/CVE-2016-8693 https://access.redhat.com/security/cve/CVE-2016-8883 https://access.redhat.com/security/cve/CVE-2016-8884 https://access.redhat.com/security/cve/CVE-2016-8885 https://access.redhat.com/security/cve/CVE-2016-9262 https://access.redhat.com/security/cve/CVE-2016-9387 https://access.redhat.com/security/cve/CVE-2016-9388 https://access.redhat.com/security/cve/CVE-2016-9389 https://access.redhat.com/security/cve/CVE-2016-9390 https://access.redhat.com/security/cve/CVE-2016-9391 https://access.redhat.com/security/cve/CVE-2016-9392 Read the Full Advisory
Red Hat Enterprise Linux Desktop (v. 6):
Source:
jasper-1.900.1-21.el6_9.src.rpm
i386:
jasper-1.900.1-21.el6_9.i686.rpm
jasper-debuginfo-1.900.1-21.el6_9.i686.rpm
jasper-libs-1.900.1-21.el6_9.i686.rpm
x86_64:
jasper-1.900.1-21.el6_9.x86_64.rpm
jasper-debuginfo-1.900.1-21.el6_9.i686.rpm
jasper-debuginfo-1.900.1-21.el6_9.x86_64.rpm
jasper-libs-1.900.1-21.el6_9.i686.rpm
jasper-libs-1.900.1-21.el6_9.x86_64.rpm
Red Hat Enterprise Linux Desktop Optional (v. 6):
i386:
jasper-debuginfo-1.900.1-21.el6_9.i686.rpm
jasper-devel-1.900.1-21.el6_9.i686.rpm
jasper-utils-1.900.1-21.el6_9.i686.rpm
x86_64:
jasper-debuginfo-1.900.1-21.el6_9.i686.rpm
jasper-debuginfo-1.900.1-21.el6_9.x86_64.rpm
jasper-devel-1.900.1-21.el6_9.i686.rpm
jasper-devel-1.900.1-21.el6_9.x86_64.rpm
jasper-utils-1.900.1-21.el6_9.x86_64.rpm
Red Hat Enterprise Linux HPC Node (v. 6):
Source:
jasper-1.900.1-21.el6_9.src.rpm
x86_64:
jasper-debuginfo-1.900.1-21.el6_9.i686.rpm
jasper-debuginfo-1.900.1-21.el6_9.x86_64.rpm
jasper-libs-1.900.1-21.el6_9.i686.rpm
jasper-libs-1.900.1-21.el6_9.x86_64.rpm
Red Hat Enterprise Linux HPC Node Optional (v. 6):
x86_64:
jasper-1.900.1-21.el6_9.x86_64.rpm
jasper-debuginfo-1.900.1-21.el6_9.i686.rpm
jasper-debuginfo-1.900.1-21.el6_9.x86_64.rpm
jasper-devel-1.900.1-21.el6_9.i686.rpm
Read the Full Advisory
An update for jasper is now available for Red Hat Enterprise Linux 6 andRed Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Enterprise Linux Client (v. 7) - x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64
Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64
Red Hat Enterprise Linux HPC Node (v. 6) - x86_64
Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64
Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
1254242 - CVE-2015-5203 jasper: integer overflow in jas_image_cmpt_create()
1255710 - CVE-2015-5221 jasper: use-after-free and double-free flaws in mif_process_cmpt()
1298135 - CVE-2016-1867 jasper: out-of-bounds read in jpc_pi_nextcprl()
1302636 - CVE-2016-2089 jasper: matrix rows_ NULL pointer dereference in jas_matrix_clip()
1314466 - CVE-2016-1577 jasper: double free issue in jas_iccattrval_destroy()
1314472 - CVE-2016-2116 jasper: memory leak in jas_iccprof_createfrombuf()
1385499 - CVE-2016-8690 CVE-2016-8884 CVE-2016-8885 jasper: missing jas_matrix_create() parameter checks
1385502 - CVE-2016-8691 CVE-2016-8692 jasper: missing SIZ marker segment XRsiz and YRsiz fields range check
1385507 - CVE-2016-8693 jasper: incorrect handling of bufsize 0 in mem_resize()
1388840 - CVE-2016-10249 jasper: integer overflow in jas_matrix_create()
1388870 - CVE-2016-8883 jasper: reachable asserts in jpc_dec_tiledecode()
1393882 - CVE-2016-9262 jasper: integer truncation in jas_image_cmpt_create()
1396959 - CVE-2016-9387 jasper: integer overflow in jpc_dec_process_siz()
1396962 - CVE-2016-9388 jasper: reachable assertions in RAS encoder/decoder
1396963 - CVE-2016-9389 jasper: reachable assertions caused by insufficient component domains checks in ICT/RCT in JPC codec
1396965 - CVE-2016-9390 jasper: insufficient SIZ marker tilexoff and tileyoff checks
Get the latest Linux and open source security news straight to your inbox.