Mageia 2020-0337: jasper security update
Summary
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote
attackers to cause a denial of service (invalid read) via a crafted image
(CVE-2017-6851).
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in
JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted
image (CVE-2017-6852).
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based
buffer over-read and application crash) via a crafted image, related to the
jp2_decode function in libjasper/jp2/jp2_dec.c (CVE-2017-9782).
There is a reachable assertion abort in the function jpc_dec_process_sot() in
jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service
attack by triggering an unexpected jpc_ppmstabtostreams return value (CVE-2017-13745).
There is a reachable assertion abort in the function jpc_dec_process_siz() in
jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of
service attack (CVE-2017-13746).
There...
References
- https://bugs.mageia.org/show_bug.cgi?id=27045
- - https://security.gentoo.org/glsa/201908-03
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6851
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6852
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9782
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13745
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13746
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13748
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13749
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13750
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13751
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14132
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9252
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18873
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19139
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19543
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20570
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20622
Resolution
MGASA-2020-0337 - Updated jasper packages fix security vulnerabilities
SRPMS
- 7/core/jasper-2.0.19-1.mga7