|Description||An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)|
Vulnerable and fixed packages
The table below lists information on source packages.
|jasper (PTS)||jessie, jessie (lts)||1.900.1-debian1-2.4+deb8u11||fixed|
The information below is based on the following data on fixed versions.
|Package||Type||Release||Fixed Version||Urgency||Origin||Debian Bugs|
[jessie] - jasper <postponed> (Code appears to work correctly but wait for more information)
This issue is reproducible with ASAN, however without ASAN the guard,
introduced with the fix for CVE-2014-8138, works as expected and
jasper terminates properly. Still I am going to mark this bug as
postponed until we receive feedback from upstream.
[wheezy] - jasper <postponed> (probably a false-positive)