Lucene search

K
osvGoogleOSV:DLA-138-1
HistoryJan 28, 2015 - 12:00 a.m.

jasper - security update

2015-01-2800:00:00
Google
osv.dev
8

0.093 Low

EPSS

Percentile

94.7%

An off-by-one flaw, leading to a heap-based buffer overflow
(CVE-2014-8157), and an unrestricted stack memory use flaw
(CVE-2014-8158) were found in JasPer, a library for manipulating
JPEG-2000 files. A specially crafted file could cause an application
using JasPer to crash or, possibly, execute arbitrary code.

For Debian 6 Squeeze, these issues have been fixed in jasper version 1.900.1-7+squeeze4