jasper 1.900.1-13ubuntu0.2 source package in Ubuntu

Changelog

jasper (1.900.1-13ubuntu0.2) precise-security; urgency=medium

  * SECURITY UPDATE: denial of service via crafted ICC color profile
    - debian/patches/05-CVE-2014-8137.patch: prevent double-free in
      src/libjasper/base/jas_icc.c, remove assert in
      src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8137
  * SECURITY UPDATE: denial of service or code execution via invalid
    channel number
    - debian/patches/06-CVE-2014-8138.patch: validate channel number in
      src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8138
  * SECURITY UPDATE: denial of service or code execution via off-by-one
    - debian/patches/07-CVE-2014-8157.patch: fix off-by-one in
      src/libjasper/jpc/jpc_dec.c.
    - CVE-2014-8157
  * SECURITY UPDATE: denial of service or code execution via memory
    corruption
    - debian/patches/08-CVE-2014-8158.patch: remove HAVE_VLA to use more
      sensible buffer sizes in src/libjasper/jpc/jpc_qmfb.c.
    - CVE-2014-8158
 -- Marc Deslauriers <email address hidden>   Thu, 22 Jan 2015 13:00:54 -0500

Upload details

Uploaded by:
Marc Deslauriers on 2015-01-22
Uploaded to:
Precise
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
graphics
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
jasper_1.900.1.orig.tar.gz 1.1 MiB 6cf104e2811f6088ca1dc76d87dd27c55178d3ccced20db8858d28ae22911a94
jasper_1.900.1-13ubuntu0.2.debian.tar.gz 33.8 KiB 91c1520bc040f9c381bf62063f753d569a7e55cc2e51687ff4d48440296ae582
jasper_1.900.1-13ubuntu0.2.dsc 1.9 KiB 82b4c8b47ae975df0806a25323739132d7989912a0c870d912c0a0d4f8df95bc

View changes file

Binary packages built by this source

libjasper-dev: Development files for the JasPer JPEG-2000 library

 JasPer is a collection of software (i.e., a library and application programs)
 for the coding and manipulation of images. This software can handle image
 data in a variety of formats. One such format supported by JasPer is the
 JPEG-2000 format defined in ISO/IEC 15444-1:2000.
 .
 This package contains the static library and headers.

libjasper-runtime: Programs for manipulating JPEG-2000 files

 JasPer is a collection of software (i.e., a library and application programs)
 for the coding and manipulation of images. This software can handle image
 data in a variety of formats. One such format supported by JasPer is the
 JPEG-2000 format defined in ISO/IEC 15444-1:2000.
 .
 This package contains programs for manipulating JPEG-2000 files.

libjasper1: JasPer JPEG-2000 runtime library

 JasPer is a collection of software (i.e., a library and application programs)
 for the coding and manipulation of images. This software can handle image
 data in a variety of formats. One such format supported by JasPer is the
 JPEG-2000 format defined in ISO/IEC 15444-1:2000.
 .
 This package contains the shared library.