jasper 1.900.1-debian1-2ubuntu0.2 source package in Ubuntu

Changelog

jasper (1.900.1-debian1-2ubuntu0.2) utopic-security; urgency=medium

  * SECURITY UPDATE: denial of service via crafted ICC color profile
    - debian/patches/05-CVE-2014-8137.patch: prevent double-free in
      src/libjasper/base/jas_icc.c, remove assert in
      src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8137
  * SECURITY UPDATE: denial of service or code execution via invalid
    channel number
    - debian/patches/06-CVE-2014-8138.patch: validate channel number in
      src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8138
  * SECURITY UPDATE: denial of service or code execution via off-by-one
    - debian/patches/07-CVE-2014-8157.patch: fix off-by-one in
      src/libjasper/jpc/jpc_dec.c.
    - CVE-2014-8157
  * SECURITY UPDATE: denial of service or code execution via memory
    corruption
    - debian/patches/08-CVE-2014-8158.patch: remove HAVE_VLA to use more
      sensible buffer sizes in src/libjasper/jpc/jpc_qmfb.c.
    - CVE-2014-8158
 -- Marc Deslauriers <email address hidden>   Thu, 22 Jan 2015 12:49:54 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Utopic
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
graphics
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
jasper_1.900.1-debian1.orig.tar.gz 1.1 MiB 7276e8407080d8263b39aeac8305032b0534c7df25bf02718b3944711e3c81d7
jasper_1.900.1-debian1-2ubuntu0.2.debian.tar.xz 29.0 KiB 9605ffecec2258b3803c15f78681cce488ada33ba39345a69e9410a2a86e16d1
jasper_1.900.1-debian1-2ubuntu0.2.dsc 2.0 KiB 4c299e9d2c99ccfc0639cfd829f574993b6be44f71aee71ed8105f86f12e9daa

View changes file

Binary packages built by this source

libjasper-dev: No summary available for libjasper-dev in ubuntu utopic.

No description available for libjasper-dev in ubuntu utopic.

libjasper-runtime: No summary available for libjasper-runtime in ubuntu utopic.

No description available for libjasper-runtime in ubuntu utopic.

libjasper1: No summary available for libjasper1 in ubuntu utopic.

No description available for libjasper1 in ubuntu utopic.