ArchLinux: 201508-10: jasper: denial of service
Summary
A double free issue has been discovered in the function jasper_image_stop_load. This vulnerability can be triggered by loading a specially crafted image through jasper.
Resolution
Upgrade to 1.900.1-14.
# pacman -Syu "jasper>=1.900.1-14"
The problem has not been fixed upstream yet.
References
https://seclists.org/oss-sec/2015/q3/366 https://access.redhat.com/security/cve/CVE-2015-5203
Workaround
None.