Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 624986 - media-libs/jasper-2.0.12 CVE-2017-6850, CVE-2017-9782
Summary: media-libs/jasper-2.0.12 CVE-2017-6850, CVE-2017-9782
Status: RESOLVED DUPLICATE of bug 614030
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Linux bug wranglers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-07-14 12:17 UTC by Andrey Ovcharov
Modified: 2017-07-14 12:18 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andrey Ovcharov 2017-07-14 12:17:14 UTC
https://nvd.nist.gov/vuln/detail/CVE-2017-6850

"The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image."

https://nvd.nist.gov/vuln/detail/CVE-2017-9782

"JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c."
Comment 1 Andrey Ovcharov 2017-07-14 12:18:14 UTC

*** This bug has been marked as a duplicate of bug 614030 ***