ELA-72-1 jasper security update

buffer overflows

2019-01-03
Packagejasper
Version1.900.1-13+deb7u8
Related CVEs CVE-2018-19540 CVE-2018-19541 CVE-2018-20570 CVE-2018-20584 CVE-2018-20622


Several flaws were corrected in Jasper, a JPEG 2000 image library. Heap-based buffer overflows may lead to memory corruption, the exposure of sensitive information or the execution of arbitrary code.



For Debian 7 Wheezy, these problems have been fixed in version 1.900.1-13+deb7u8.

We recommend that you upgrade your jasper packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.