Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 662160 (CVE-2018-9055) - media-libs/jasper: Multiple vulnerabilities (CVE-2018-9055)
Summary: media-libs/jasper: Multiple vulnerabilities (CVE-2018-9055)
Status: RESOLVED FIXED
Alias: CVE-2018-9055
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-07-26 07:01 UTC by GLSAMaker/CVETool Bot
Modified: 2019-08-09 20:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2018-07-26 07:01:30 UTC
CVE-2018-9154 (https://nvd.nist.gov/vuln/detail/CVE-2018-9154):
  There is a reachable abort in the function jpc_dec_process_sot in
  libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial
  of service attack by triggering an unexpected jas_alloc2 return value, a
  different vulnerability than CVE-2017-13745.

CVE-2018-9055 (https://nvd.nist.gov/vuln/detail/CVE-2018-9055):
  JasPer 2.0.14 allows denial of service via a reachable assertion in the
  function jpc_firstone in libjasper/jpc/jpc_math.c.
Comment 1 Yury German Gentoo Infrastructure gentoo-dev Security 2018-11-12 23:53:55 UTC
CVE-2018-9154 has been rejected => CVE-2017-13753
https://nvd.nist.gov/vuln/detail/CVE-2018-9154
Points to CVE-2017-13753 which also been rejected ==> CVE-2016-9396
https://nvd.nist.gov/vuln/detail/CVE-2017-13753
Removing - Rejected CVE Leaving valid CVE

CVE-2018-9055 - 
https://github.com/mdadams/jasper/issues/172
Comment 2 Larry the Git Cow gentoo-dev 2019-07-14 10:30:16 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c70fe723dcfe0fabab75f3a76942207018e83e1f

commit c70fe723dcfe0fabab75f3a76942207018e83e1f
Author:     David Seifert <soap@gentoo.org>
AuthorDate: 2019-07-14 10:29:20 +0000
Commit:     David Seifert <soap@gentoo.org>
CommitDate: 2019-07-14 10:29:20 +0000

    package.mask: Last rite media-libs/jasper
    
    Bug: https://bugs.gentoo.org/601068
    Bug: https://bugs.gentoo.org/614028
    Bug: https://bugs.gentoo.org/614032
    Bug: https://bugs.gentoo.org/614566
    Bug: https://bugs.gentoo.org/619120
    Bug: https://bugs.gentoo.org/624988
    Bug: https://bugs.gentoo.org/629286
    Bug: https://bugs.gentoo.org/635552
    Bug: https://bugs.gentoo.org/662160
    Bug: https://bugs.gentoo.org/674154
    Bug: https://bugs.gentoo.org/674214
    Bug: https://bugs.gentoo.org/684826
    Bug: https://bugs.gentoo.org/689784
    Signed-off-by: David Seifert <soap@gentoo.org>

 profiles/base/package.use.mask | 23 +++++++++++++++++++++++
 profiles/package.mask          |  7 +++++++
 2 files changed, 30 insertions(+)
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2019-08-09 20:39:45 UTC
This issue was resolved and addressed in
 GLSA 201908-03 at https://security.gentoo.org/glsa/201908-03
by GLSA coordinator Aaron Bauman (b-man).