jasper 1.900.1-14ubuntu3.2 source package in Ubuntu

Changelog

jasper (1.900.1-14ubuntu3.2) trusty-security; urgency=medium

  * SECURITY UPDATE: denial of service via crafted ICC color profile
    - debian/patches/05-CVE-2014-8137.patch: prevent double-free in
      src/libjasper/base/jas_icc.c, remove assert in
      src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8137
  * SECURITY UPDATE: denial of service or code execution via invalid
    channel number
    - debian/patches/06-CVE-2014-8138.patch: validate channel number in
      src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8138
  * SECURITY UPDATE: denial of service or code execution via off-by-one
    - debian/patches/07-CVE-2014-8157.patch: fix off-by-one in
      src/libjasper/jpc/jpc_dec.c.
    - CVE-2014-8157
  * SECURITY UPDATE: denial of service or code execution via memory
    corruption
    - debian/patches/08-CVE-2014-8158.patch: remove HAVE_VLA to use more
      sensible buffer sizes in src/libjasper/jpc/jpc_qmfb.c.
    - CVE-2014-8158
 -- Marc Deslauriers <email address hidden>   Thu, 22 Jan 2015 13:00:10 -0500

Upload details

Uploaded by:
Marc Deslauriers on 2015-01-22
Uploaded to:
Trusty
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
graphics
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
jasper_1.900.1.orig.tar.gz 1.1 MiB 6cf104e2811f6088ca1dc76d87dd27c55178d3ccced20db8858d28ae22911a94
jasper_1.900.1-14ubuntu3.2.debian.tar.gz 33.6 KiB a0015919fde01e93b36e46b6f85faeeac27b5c81b105b977048a7948a8580239
jasper_1.900.1-14ubuntu3.2.dsc 1.9 KiB e2017a752d6348ea02ecdce97002dfcc55c9e845112a86762b610986b6a85542

View changes file

Binary packages built by this source

libjasper-dev: Development files for the JasPer JPEG-2000 library

 JasPer is a collection of software (i.e., a library and application programs)
 for the coding and manipulation of images. This software can handle image
 data in a variety of formats. One such format supported by JasPer is the
 JPEG-2000 format defined in ISO/IEC 15444-1:2000.
 .
 This package contains the static library and headers.

libjasper-runtime: Programs for manipulating JPEG-2000 files

 JasPer is a collection of software (i.e., a library and application programs)
 for the coding and manipulation of images. This software can handle image
 data in a variety of formats. One such format supported by JasPer is the
 JPEG-2000 format defined in ISO/IEC 15444-1:2000.
 .
 This package contains programs for manipulating JPEG-2000 files.

libjasper1: JasPer JPEG-2000 runtime library

 JasPer is a collection of software (i.e., a library and application programs)
 for the coding and manipulation of images. This software can handle image
 data in a variety of formats. One such format supported by JasPer is the
 JPEG-2000 format defined in ISO/IEC 15444-1:2000.
 .
 This package contains the shared library.