Login
Newsletter
Werbung

Sicherheit: Denial of Service in jasper
Aktuelle Meldungen Distributionen
Name: Denial of Service in jasper
ID: TLSA-2007-39
Distribution: TurboLinux
Plattformen: Turbolinux FUJI, Turbolinux 10 Server, Turbolinux 10 Server x64 Edition, Turbolinux 10 Desktop, Turbolinux 10 F..., Turbolinux Home, Turbolinux Multimedia, Turbolinux Personal, TurboLinux wizpy
Datum: Do, 2. August 2007, 03:50
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721
Applikationen: JasPer

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2007-39
http://www.turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------

Original released date : 01 Aug 2007
Last revised : 01 Aug 2007

Package: jasper

Summary: Jasper denial of service

More information:
Jasper is a collection of software (i.e., a library and application
programs)
for the coding and manipulation of images. This software can handle image
data
in a variety of formats. One such format supported by Jasper is the
JPEG-2000
format defined in ISO/IEC 15444-1:2000.

Remote user-assisted attackers to cause a denial of service.

Impact:
The application crash and possibly corrupt the heap via malformed image
files.

Affected Products:
- wizpy
- Turbolinux FUJI
- Turbolinux 10 Server x64 Edition
- Turbolinux 10 Server
- Turbolinux Home
- Turbolinux 10 F...
- Turbolinux 10 Desktop
- Turbolinux Multimedia
- Turbolinux Personal


<wizpy>

Source Packages
Size: MD5

jasper-1.701.0-2.src.rpm
1331524 04d8cc70c0ad4fc56c950eea952663ef

Binary Packages
Size: MD5

jasper-1.701.0-2.i386.rpm
130066 2dc4e7d729018e625b73b5476a904cb3

<Turbolinux FUJI>

Source Packages
Size: MD5

jasper-1.701.0-2.src.rpm
1331524 8b1896c0c66252d83b836b6f00b3bd42

Binary Packages
Size: MD5

jasper-1.701.0-2.i686.rpm
159856 9ff331d5d36a458ffdc82d6fa24202ea
jasper-devel-1.701.0-2.i686.rpm
188047 fe87f8c00f31397da1a6c51c05f6bacd

<Turbolinux 10 Server x64 Edition>

Source Packages
Size: MD5

jasper-1.701.0-2.src.rpm
1331524 a5bec344a249cb90d70ac2579926951e

Binary Packages
Size: MD5

jasper-1.701.0-2.x86_64.rpm
158437 a228a3b5a0758216f9371ce4075d3155
jasper-devel-1.701.0-2.x86_64.rpm
163620 3d2a2333a9b7bef0a17e69400f50e0e9

<Turbolinux 10 Server>

Source Packages
Size: MD5

jasper-1.701.0-2.src.rpm
1331524 73ff87a657f8ed88f6dfae1b39326360

Binary Packages
Size: MD5

jasper-1.701.0-2.i586.rpm
146402 ed49f09cd213e58010470b4ebb13b03a
jasper-devel-1.701.0-2.i586.rpm
159502 521c781a7dc82577541d10d0d2960acd

<Turbolinux 10 Desktop, Turbolinux 10 F..., Turbolinux Home, Turbolinux
Multimedia, Turbolinux Personal>

Source Packages
Size: MD5

jasper-1.700.2-5.src.rpm
1495512 9bba6196753bf169d8ec7e385912c139

Binary Packages
Size: MD5

jasper-1.700.2-5.i586.rpm
146474 0b200bf55268abf2ed4c22d1960fdf0f


References:

CVE
[CVE-2007-2721]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721

--------------------------------------------------------------------------
Revision History
01 Aug 2007
--------------------------------------------------------------------------

Copyright(C) 2007 Turbolinux, Inc. All rights reserved.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFGsBojK0LzjOqIJMwRAmUvAKCQv9wrfHQR2mqDOjs7IA8ZzZj2dwCgt3Hc
evOXH6aLl4qyhNzq9X18IKs=
=6gKe
-----END PGP SIGNATURE-----
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung