Debian 10222 Published by

A jasper security update has been released for Debian GNU/Linux 8 Extended LTS to address two security issues.



ELA-361-1 jasper security update

Package jasper
Version 1.900.1-debian1-2.4+deb8u9
Related CVEs CVE-2021-26926 CVE-2021-26927

CVE-2021-26926

A heap buffer overflow vulnerability was discovered
in JasPer, through jp2_dec.c in the jp2_decode() function.

CVE-2021-26927

A null pointer access was discovered in JasPer, through
jp2_dec.c in the jp2_decode() function.
For Debian 8 jessie, these problems have been fixed in version 1.900.1-debian1-2.4+deb8u9.

We recommend that you upgrade your jasper packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-361-1 jasper security update