Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 198499 - media-libs/netpbm includes vulnerable libjasper code (CVE-2007-2721)
Summary: media-libs/netpbm includes vulnerable libjasper code (CVE-2007-2721)
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/27489/
Whiteboard: B3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-11-08 22:09 UTC by Pierre-Yves Rofes (RETIRED)
Modified: 2007-11-10 09:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-08 22:09:36 UTC
same than #179159
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-08 22:13:31 UTC
patch is in /usr/portage/media-libs/jasper/files/jasper-overflow-fix.patch

Only change is  "uint_fast16_t" replaced with "uint_fast32_t", but apart from that it should apply just fine.

Graphics, please provide a fixed ebuild.
Comment 2 SpanKY gentoo-dev 2007-11-10 09:14:01 UTC
netpbm forces external jasper linking like any correct package should

if you find that's not the case, let me know