Add patches for all current CVEs. ------------------------------------------------------------------------------- - ChangeLog:
* Sat Dec 13 2014 Michael Cronenworth <mike@cchtml.com> - 1.900.1-24 - Apply all native patches for CVEs * Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.900.1-23 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.900.1-22 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1170652 - CVE-2014-9029 mingw-jasper: jasper: incorrect component number check in COC, RGN and QCC marker segment decoders (oCERT-2014-009) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1170652 [ 2 ] Bug #765664 - CVE-2011-4516 CVE-2011-4517 mingw32-jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=765664 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update mingw-jasper' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.