USN-2434-1: JasPer vulnerability
8 December 2014
JasPer could be made to crash or run programs as your login if it opened a specially crafted file.
- jasper - Library for manipulating JPEG-2000 files
Jose Duart discovered that JasPer incorrectly handled certain malformed
JPEG-2000 image files. If a user were tricked into opening a specially
crafted JPEG-2000 image file, a remote attacker could cause JasPer to crash
or possibly execute arbitrary code with user privileges.
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.
- USN-2434-2: ghostscript, libgs8