Open grahamc opened 7 years ago
Working, updating to latest version
Added some additional checking to prevent a potential integer overflow; Not sure if this is a commit to fix this issue; That msg came from a commit msg for this software
Edit: I dont think it does, but could be wrong
Hm, the upstream issue is open. It also has a testcase, interesting.
imginfo -f 00126-jasper-heapoverflow-jpc_dec_decodepkt
gives imginfo: /tmp/nix-build-jasper-2.0.10.drv-0/jasper-2.0.10/src/libjasper/jpc/jpc_t2cod.c:305: jpc_pi_nextrpcl: Assertion `pi->prcno < pi->pirlvl->numprcs' failed.
Does the updated version do the same?
… Yes it does.
If only we could snooze this issue until the upstream issue mdadams/jasper#114 gets closed or mentioned in PR/commit… (being able to translate comments from the upstream issue would also be nice)
fwiw I've merged the .12 update, because they're usually worth updating to. This issue is still one.
The patches I madee are:
master: 6c17ad677c4970c87e8562574ea7e6fbf12b0813 release-16.09: 4368adb6ac631b3bdbb071e96dfc545c1f8f92e1 release-17.03: beab3073c9caec3e6b67558efc6111bb68c7a2ab
Here is a report from the oss-security mailing list for Vulnerability Roundup 27.
Skip to First Email
Instructions:
Identification
Identify if we have the software, in 16.09, 17.03, and unstable. Then determine if we are vulnerable, and make a comment with your findings. It can also be helpful to specify if you think there is a patch, or if it can be fixed via a general update.
Example:
IMPORTANT: If you believe there are possibly related issues, bring them up on the parent issue!
Patching
Start by commenting on this issue saying you're working on a patch. This way, we don't duplicate work.
If you open a pull request, tag this issue and the master issue for the roundup.
If you commit the patch directly to a branch, please leave a comment on this issue with the branch and the commit hash, example:
Skip to First Email
Upon Completion ...
Info
Triage Indicator:
Should the search term be changed from
jasper
? Suggest a new package search by commenting:Known CVEs: CVE-2017-6852
Skip to End
Wed, 25 Jan 2017 10:16:01 +0100 Agostino Sarubbo,
2979113.NTRsFXjtRy@blackgate
Skip to End
Wed, 25 Jan 2017 10:41:17 +0100 Salvatore Bonaccorso,
20170125094117.GC30424@lorien.valinor.li
Skip to End
Mon, 13 Mar 2017 12:14:57 +0100 Agostino Sarubbo,
4259614.1heLH0LskT@blackgate
Skip to End