Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 618490 - media-libs/jasper multiple vulnerabilities
Summary: media-libs/jasper multiple vulnerabilities
Status: RESOLVED OBSOLETE
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://github.com/mdadams/jasper
Whiteboard: B3 [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-15 04:21 UTC by Volkan
Modified: 2017-05-15 15:39 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Volkan 2017-05-15 04:21:44 UTC
(CVE-2016-9397) CVE-2016-9397 jasper: reachable assertion in jpc_dequantize()
-- https://bugzilla.redhat.com/show_bug.cgi?id=1396979

(CVE-2016-9396) - media-libs/jasper: reachable assertion in JPC_NOMINALGAIN()
-- https://bugzilla.redhat.com/show_bug.cgi?id=1396978

(CVE-2016-9398) - media-libs/jasper: reachable assertion in jpc_floorlog2()
-- https://bugzilla.redhat.com/show_bug.cgi?id=1396980

(CVE-2017-6852) - media-libs/jasper: Out of bounds heap read in jpc_dec_decodepkt
-- https://bugzilla.redhat.com/show_bug.cgi?id=1434459
-- https://bugs.gentoo.org/show_bug.cgi?id=614032

(CVE-2017-6851) - media-libs/jasper: Invalid memory read in jas_matrix_bindsub (jas_seq.c)
-- https://bugzilla.redhat.com/show_bug.cgi?id=1435324

(CVE-2017-5505) - media-libs/jasper: Invalid memory read in jas_matrix_asl
-- https://bugzilla.redhat.com/show_bug.cgi?id=1416068

(CVE-2017-5504) - media-libs/jasper: Invalid memory read in jpc_undo_roi
--https://bugzilla.redhat.com/show_bug.cgi?id=1416069

(CVE-2017-5503) - media-libs/jasper: invalid memory write in dec_clnpass() 
--https://bugzilla.redhat.com/show_bug.cgi?id=1416056
Comment 1 Agostino Sarubbo gentoo-dev 2017-05-15 06:59:23 UTC
These bugs were already been filed. Since they were filed separately, I don't know to which bug mark as a duplicate, so I'm closing as OBSOLETE