MGASA-2016-0298

Source
https://advisories.mageia.org/MGASA-2016-0298.html
Import Source
https://advisories.mageia.org/MGASA-2016-0298.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0298
Upstream
  • CVE-2015-5203
  • CVE-2015-5221
Published
2016-09-16T09:27:13Z
Modified
2026-04-16T06:26:04.344049787Z
Summary
Updated jasper packages fix security vulnerability
Details

A double-free issue in JasPer 1.900.1 in the jasperimagestop_load() function can cause a denial of service if a specially crafted JPEG image is loaded (CVE-2015-5203).

A use-after-free which leads to double-free vulnerability was found in Jasper JPEG-2000 library, in src/libjasper/mif/mif_cod.c file (CVE-2015-5221).

References
Credits

Affected packages

Mageia:5 / jasper

Package

Name
jasper
Purl
pkg:rpm/mageia/jasper?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.900.1-20.5.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2016-0298.json"