Description: | JasPer is an implementation of Part 1 of the JPEG 2000 image compressionstandard.Multiple off-by-one flaws, leading to heap-based buffer overflows, werefound in the way JasPer decoded JPEG 2000 image files. A specially craftedfile could cause an application using JasPer to crash or, possibly, executearbitrary code. (CVE-2014-9029)A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG2000 image files. A specially crafted file could cause an application usingJasPer to crash or, possibly, execute arbitrary code. (CVE-2014-8138)A double free flaw was found in the way JasPer parsed ICC color profiles inJPEG 2000 image files. A specially crafted file could cause an applicationusing JasPer to crash or, possibly, execute arbitrary code. (CVE-2014-8137)Red Hat would like to thank oCERT for reporting these issues. oCERTacknowledges Jose Duart of the Google Security Team as the originalreporter.All JasPer users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. All applications usingthe JasPer libraries must be restarted for the update to take effect. |