MGASA-2016-0100

Source
https://advisories.mageia.org/MGASA-2016-0100.html
Import Source
https://advisories.mageia.org/MGASA-2016-0100.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0100
Related
Published
2016-03-07T18:03:54Z
Modified
2016-03-07T17:58:22Z
Summary
Updated jasper packages fix security vulnerabilities
Details

Updated jasper packages fix security vulnerabilities:

The jasmatrixclip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image (CVE-2016-2089).

Jacob Baines discovered that a double free vulnerability in the jasiccattrvaldestroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file (CVE-2016-1577).

Tyler Hicks discovered that a memory leak in the jasiccprofcreatefrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file (CVE-2016-2116).

References
Credits

Affected packages

Mageia:5 / jasper

Package

Name
jasper
Purl
pkg:rpm/mageia/jasper?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.900.1-20.4.mga5

Ecosystem specific

{
    "section": "core"
}