Name | CVE-2014-8158 |
Description | Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-138-1, DSA-3138-1 |
Debian Bugs | 775970 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
jasper | source | squeeze | 1.900.1-7+squeeze4 | DLA-138-1 | ||
jasper | source | wheezy | 1.900.1-13+deb7u3 | DSA-3138-1 | ||
jasper | source | (unstable) | 1.900.1-debian1-2.4 | 775970 |
http://www.ocert.org/advisories/ocert-2015-001.html