UbuntuUpdates.org

Package "jasper"

Name: jasper

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Programs for manipulating JPEG-2000 files

Latest version: 1.900.1-13
Release: precise (12.04)
Level: base
Repository: universe

Links



Other versions of "jasper" in Precise

Repository Area Version
base main 0.69
security main 1.900.1-13ubuntu0.3
security universe 1.900.1-13ubuntu0.3
updates universe 1.900.1-13ubuntu0.3
updates main 1.900.1-13ubuntu0.3

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: *DELETED* 2012-03-06 11:29:42 UTC
No changelog for deleted or moved packages.

Version: 1.900.1-13 2012-01-11 18:02:55 UTC

jasper (1.900.1-13) unstable; urgency=high

  * Fix CVE-2011-4516 and CVE-2011-4517: Two buffer overflow issues possibly
    exploitable via specially crafted input files (Closes: #652649)
    Thanks to Red Hat and Michael Gilbert

 -- Roland Stigge Wed, 04 Jan 2012 19:14:40 +0100

Source diff to previous version
652649 jasper: Fix for CVE-2011-4516 and CVE-2011-4517 - Debian Bug report logs
CVE-2011-4516 Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitra
CVE-2011-4517 The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows

Version: 1.900.1-12ubuntu1 2011-12-19 18:03:24 UTC

jasper (1.900.1-12ubuntu1) precise; urgency=low

  * SECURITY UPDATE: denial of service and possible code execution via
    heap-based buffer overflows.
    - debian/patches/03-CVE-2011-451x.patch: validate compparms->numrlvls
      and allocate proper size in src/libjasper/jpc/jpc_cs.c.
    - CVE-2011-4516
    - CVE-2011-4517

 -- Marc Deslauriers Mon, 19 Dec 2011 09:36:08 -0500

CVE-2011-4516 Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitra
CVE-2011-4517 The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows

Version: *DELETED* 2011-12-18 14:48:14 UTC
No changelog for deleted or moved packages.



About   -   Send Feedback to @ubuntu_updates