Upstream details at : https://access.redhat.com/errata/RHSA-2017:1208.html. CentOS Errata and Security Advisory 2017:1208 Important Upstream details at : https://access.redhat.com/errata/RHSA-2017:1208.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: bf4bec0731557d9200609d59f46d1b66da039a1887828d2d477be9b93675a137 jasper-1.900.1-30.el7_3.x86_64.rpm 094699ed29af7ed7ba8dffbdbcd8cd345339acf9b4da7a519d1bfcea7bef23b0 jasper-devel-1.900.1-30.el7_3.i686.rpm d7c8e089c540c9d1ed779130e51a7637fd242cdea676c545216a2cb49fdd77a9 jasper-devel-1.900.1-30.el7_3.x86_64.rpm 33528f9a2f5eaffc09abaed6f5b81f336815820969406a24dfb7526d587ed54b jasper-libs-1.900.1-30.el7_3.i686.rpm 63ee65983ed5bd9f8d2516f4066d3642cdff69f63b5251a52470094e7a816150 jasper-libs-1.900.1-30.el7_3.x86_64.rpm a7863af6605c1c32063a611a530c0b4da2312b98fb2da4138e4071fa8f6762c2 jasper-utils-1.900.1-30.el7_3.x86_64.rpm Source: 37135c918505fca6233f9ab55193602bb9ed97dcde43a50ed6f2dae3a45038fc jasper-1.900.1-30.el7_3.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
New jasper packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] jasper (SSA:2015-302-02) New jasper packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/jasper-1.900.1-i486-4_slack14.1.txz: Rebuilt. Applied many security and bug fixes. Thanks to Heinz Wiesinger. For more information, see: https://www.cve.org/CVERecord?id=CVE-2008-3520 https://www.cve.org/CVERecord?id=CVE-2008-3522 https://www.cve.org/CVERecord?id=CVE-2011-4516 https://www.cve.org/CVERecord?id=CVE-2011-4517 https://www.cve.org/CVERecord?id=CVE-2014-8137 https://www.cve.org/CVERecord?id=CVE-2014-8138 https://www.cve.org/CVERecord?id=CVE-2014-8157 https://www.cve.org/CVERecord?id=CVE-2014-8158 https://www.cve.org/CVERecord?id=CVE-2014-9029 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/jasper-1.900.1-i486-3_slack13.0.txz Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/jasper-1.900.1-x86_64-3_slack13.0.txz Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/jasper-1.900.1-i486-4_slack13.1.txz Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/jasper-1.900.1-x86_64-4_slack13.1.txz Updated package for Slackware13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/jasper-1.900.1-i486-4_slack13.37.txz Updated package for Slackware x86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/jasper-1.900.1-x86_64-4_slack13.37.txz Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/jasper-1.900.1-i486-4_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/jasper-1.900.1-x86_64-4_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/jasper-1.900.1-i486-4_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/jasper-1.900.1-x86_64-4_slack14.1.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: 5156625217cd39753e427d30a8e994d2 jasper-1.900.1-i486-3_slack13.0.txz Slackware x86_64 13.0 package: 6d7e1fe5d90acf882a799c7a4f07a447 jasper-1.900.1-x86_64-3_slack13.0.txz Slackware 13.1 package: 4af3cca993d4b50be8cc59a9599bfc3e jasper-1.900.1-i486-4_slack13.1.txz Slackware x86_64 13.1 package: 3c2da5e24db15cb4ac0436bb9c99ce31 jasper-1.900.1-x86_64-4_slack13.1.txz Slackware 13.37 package: e28b5780bb6bc2268d6d0aa3e934857c jasper-1.900.1-i486-4_slack13.37.txz Slackware x86_64 13.37 package: 3ed6279730f6166b9caeaa0057e70afe jasper-1.900.1-x86_64-4_slack13.37.txz Slackware 14.0 package: 379669370567a56e10524cd8a617b9d5 jasper-1.900.1-i486-4_slack14.0.txz Slackware x86_64 14.0 package: 709a08d0f7c1cc2ff137413535b8733b jasper-1.900.1-x86_64-4_slack14.0.txz Slackware 14.1 package: 0eb7e527854fbf3b2c72632015466069 jasper-1.900.1-i486-4_slack14.1.txz Slackware x86_64 14.1 package: 75303d94123548515bc2913d83ec52cc jasper-1.900.1-x86_64-4_slack14.1.txz Slackware -currentpackage: f1a1b8c0d3efe48c47665b1d88bcf8e9 l/jasper-1.900.1-i586-5.txz Slackware x86_64 -current package: 31b75bd030af924b1a23e8763b9570e9 l/jasper-1.900.1-x86_64-5.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg jasper-1.900.1-i486-4_slack14.1.txz +-----+ . Explore fresh jasper tools for Slackware environments targeting essential security vulnerabilities. Upgrade immediately to ensure your safety.. Jasper Update, Slackware Security, Critical Update. . Severity: Critical. LinuxSecurity.com Team
The packages jasper before version 1.900.1-14 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201508-10 ========================================= Severity: Medium Date : 2015-08-26 CVE-ID : CVE-2015-5203 Package : jasper Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The packages jasper before version 1.900.1-14 is vulnerable to denial of service. Resolution ========= Upgrade to 1.900.1-14. # pacman -Syu "jasper> =1.900.1-14" The problem has not been fixed upstream yet. Workaround ========= None. Description ========== A double free issue has been discovered in the function jasper_image_stop_load. This vulnerability can be triggered by loading a specially crafted image through jasper. Impact ===== A remote attacker is able to send a specially crafted image that triggers a double free leading to denial of service. References ========= https://seclists.org/oss-sec/2015/q3/366 https://access.redhat.com/security/cve/CVE-2015-5203 . The Arch Linux Security Advisory ASA-201512-22 highlights a critical vulnerability in the libcups package, leading to potential exploitation. User action to update is advised.. jasper package, Arch Linux advisory, DoS threat. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.