Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in JasPer
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in JasPer
ID: USN-1315-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04, Ubuntu 11.10
Datum: Di, 20. Dezember 2011, 23:15
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4516
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4517
Applikationen: JasPer

Originalnachricht


--===============1267193708461105631==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-0LT7Mfyy3dGsFjkS5KIp"


--=-0LT7Mfyy3dGsFjkS5KIp
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1315-1
December 20, 2011

jasper vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

JasPer could be made to crash or run programs as your login if it opened a
specially crafted file.

Software Description:
- jasper: Library for manipulating JPEG-2000 files

Details:

Jonathan Foote discovered that JasPer incorrectly handled certain malformed
JPEG-2000 image files. If a user were tricked into opening a specially
crafted JPEG-2000 image file, a remote attacker could cause JasPer to crash
or possibly execute arbitrary code with user privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
libjasper1 1.900.1-7ubuntu2.11.10.1

Ubuntu 11.04:
libjasper1 1.900.1-7ubuntu2.11.04.1

Ubuntu 10.10:
libjasper1 1.900.1-7ubuntu0.10.10.1

Ubuntu 10.04 LTS:
libjasper1 1.900.1-7ubuntu0.10.04.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1315-1
CVE-2011-4516, CVE-2011-4517

Package Information:
https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu2.11.10.1
https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu2.11.04.1
https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu0.10.10.1
https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu0.10.04.1



--ÐLT7Mfyy3dGsFjkS5KIp
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJO8KdsAAoJEGVp2FWnRL6TCl4QALnMBLByNqfYgwntvPEOoFcT
LT8WHBk64qj4ovUItHl+4XGSaE+GlhASNgvivEBFf/IvJL/gC+laxrnV4wwm9xdv
TZA0T8JJG53OH6U/CcP6n3MCjsdDtMv0MmrPFC5MWBcYMqwOJOUvhnY6vCi7aLy7
RTR+T1/wAWarVeIDjO5n6h0vZPRikEIF1AaSXeU2hPZlg1PAVhJjL5lO9duF5OGO
L2OzIj+TpAxJgZa7TmSKiNMgb5euIwAQyM5zje4xyblvrxEigVdAfJNab3uF8mVY
uIOZ7nr9rHnWct9ZG1IGLQQ2w5Afyns3SrABr81ItC/cFZ72fBPAd/JihWT6nBV/
nbsYJrNT0+ufqUjHR6i8tWISJ/fL8s++RtJpS65SfRXullEuWw6yql7gtp/E0+Rh
uNJ2aOZPsCx2FqNKA7MIrUNJkz3GEvXAyXS4ZqnDh4RD6zpHvErsxek2rtV2q0N/
BheEs2GpES3AmWhZbJDRlMkR83P95UoIYapblym+O560fTTMlZEl9jzkcjxcMidL
vX3VFpVqM6ivKyYLn91Adxtc9Rdku+j955Xj3NN4pQ8NsvEQxayeFmYulp9KE0gS
y9prJ/kZK/qs4LWQjq0ttMIQus0Wy8wHlfAvxxlmcUBtazmIw5YjUrMjhtAytk+Z
/w+lpY7b6SQZ+6TaRJj6
=NAnh
-----END PGP SIGNATURE-----

--=-0LT7Mfyy3dGsFjkS5KIp--



--===============1267193708461105631==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============1267193708461105631==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung