Vulnerability Bulletins

DSA-3138 jasper - security update

   
Affected software Debian
 
An off-by-one flaw, leading to a heap-based buffer overflow(CVE-2014-8157), and an unrestricted stack memory use flaw(CVE-2014-8158) were found in JasPer, a library for manipulatingJPEG-2000 files. A specially crafted file could cause an applicationusing JasPer to crash or, possibly, execute arbitrary code.

More info:

https://www.debian.org/security/2015/dsa-3138