Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 198499

Summary: media-libs/netpbm includes vulnerable libjasper code (CVE-2007-2721)
Product: Gentoo Security Reporter: Pierre-Yves Rofes (RETIRED) <py>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED INVALID    
Severity: minor CC: graphics+disabled
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://secunia.com/advisories/27489/
Whiteboard: B3 [ebuild]
Package list:
Runtime testing required: ---

Description Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-08 22:09:36 UTC
same than #179159
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-08 22:13:31 UTC
patch is in /usr/portage/media-libs/jasper/files/jasper-overflow-fix.patch

Only change is  "uint_fast16_t" replaced with "uint_fast32_t", but apart from that it should apply just fine.

Graphics, please provide a fixed ebuild.
Comment 2 SpanKY gentoo-dev 2007-11-10 09:14:01 UTC
netpbm forces external jasper linking like any correct package should

if you find that's not the case, let me know