Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 624986

Summary: media-libs/jasper-2.0.12 CVE-2017-6850, CVE-2017-9782
Product: Gentoo Linux Reporter: Andrey Ovcharov <sudormrfhalt>
Component: Current packagesAssignee: Gentoo Linux bug wranglers <bug-wranglers>
Status: RESOLVED DUPLICATE    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Andrey Ovcharov 2017-07-14 12:17:14 UTC
https://nvd.nist.gov/vuln/detail/CVE-2017-6850

"The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image."

https://nvd.nist.gov/vuln/detail/CVE-2017-9782

"JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c."
Comment 1 Andrey Ovcharov 2017-07-14 12:18:14 UTC

*** This bug has been marked as a duplicate of bug 614030 ***