Sync jasper 1.900.1-debian1-2.4 (main) from Debian unstable (main)

Bug #1416141 reported by Artur Rona
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
jasper (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync jasper 1.900.1-debian1-2.4 (main) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: denial of service or code execution via off-by-one
    - debian/patches/07-CVE-2014-8157.patch: fix off-by-one in
      src/libjasper/jpc/jpc_dec.c.
    - CVE-2014-8157
  * SECURITY UPDATE: denial of service or code execution via memory
    corruption
    - debian/patches/08-CVE-2014-8158.patch: remove HAVE_VLA to use more
      sensible buffer sizes in src/libjasper/jpc/jpc_qmfb.c.
    - CVE-2014-8158

Debian fixed CVEs, as well.

Changelog entries since current vivid version 1.900.1-debian1-2.3ubuntu1:

jasper (1.900.1-debian1-2.4) unstable; urgency=high

  * Non-maintainer upload.
  * Add 07-CVE-2014-8157.patch patch.
    CVE-2014-8157: dec->numtiles off-by-one check in jpc_dec_process_sot().
    (Closes: #775970)
  * Add 08-CVE-2014-8158.patch patch.
    CVE-2014-8158: unrestricted stack memory use in jpc_qmfb.c (Closes: #775970)

 -- Salvatore Bonaccorso <email address hidden> Thu, 22 Jan 2015 17:09:24 +0100

CVE References

Artur Rona (ari-tczew)
Changed in jasper (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Sebastien Bacher (seb128) wrote :

This bug was fixed in the package jasper - 1.900.1-debian1-2.4
Sponsored for Artur Rona (ari-tczew)

---------------
jasper (1.900.1-debian1-2.4) unstable; urgency=high

  * Non-maintainer upload.
  * Add 07-CVE-2014-8157.patch patch.
    CVE-2014-8157: dec->numtiles off-by-one check in jpc_dec_process_sot().
    (Closes: #775970)
  * Add 08-CVE-2014-8158.patch patch.
    CVE-2014-8158: unrestricted stack memory use in jpc_qmfb.c (Closes: #775970)

 -- Salvatore Bonaccorso <email address hidden> Thu, 22 Jan 2015 17:09:24 +0100

Changed in jasper (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.