Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 559164 (CVE-2015-5203) - <media-libs/jasper-1.900.15: Double free corruption (CVE-2015-5203)
Summary: <media-libs/jasper-1.900.15: Double free corruption (CVE-2015-5203)
Status: RESOLVED FIXED
Alias: CVE-2015-5203
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://seclists.org/oss-sec/2015/q3/366
Whiteboard: A3 [glsa cve]
Keywords:
Depends on: 559168
Blocks:
  Show dependency tree
 
Reported: 2015-08-30 14:06 UTC by Agostino Sarubbo
Modified: 2017-07-08 12:39 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-08-30 14:06:56 UTC
From ${URL} :

A new double free affecting JasPer JPEG-2000 (libjasper 1.900) has been
found triggered by function jasper_image_stop_load.
Despite this library is used by many programs (
http://www.ece.uvic.ca/~frodo/jasper/#overview), there is no one providing
support, so there is no fix so far.

The proposed patch is:
http://sourceforge.net/projects/mancha/files/sec/jasper-1.900.1_CVE-2015-5203.diff




@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Agostino Sarubbo gentoo-dev 2016-11-29 17:00:14 UTC
The first upstream version that contains the fix for this bug is 1.900.10
The first fixed version in tree was 1.900.15

So it will be fixed in the next stabilization of jasper.

I'm adding stable blocked because there are some things that seems to not work in the latest jasper regards multilib and gold/bfd
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2017-05-21 06:17:12 UTC
Arches and Maintainer(s), Thank you for your work.

No longer in tree.
GLSA Vote: No
Closing as [noglsa].
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2017-05-21 06:19:17 UTC
Added to an existing GLSA Request.
Jasper GLSA already in process, adding to it.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2017-07-08 12:39:21 UTC
This issue was resolved and addressed in
 GLSA 201707-07 at https://security.gentoo.org/glsa/201707-07
by GLSA coordinator Thomas Deutschmann (whissi).