{"id":16224,"date":"2017-05-26T16:40:35","date_gmt":"2017-05-26T07:40:35","guid":{"rendered":"https:\/\/jirak.net\/wp\/usn-3295-1-jasper-vulnerabilities\/"},"modified":"2017-05-26T16:40:35","modified_gmt":"2017-05-26T07:40:35","slug":"usn-3295-1-jasper-vulnerabilities","status":"publish","type":"post","link":"https:\/\/jirak.net\/wp\/usn-3295-1-jasper-vulnerabilities\/","title":{"rendered":"USN-3295-1: JasPer vulnerabilities"},"content":{"rendered":"<p>USN-3295-1: JasPer vulnerabilities<\/p>\n<h2>Ubuntu Security Notice USN-3295-1<\/h2>\n<p><em>18th May, 2017<\/em><\/p>\n<h3>jasper vulnerabilities<\/h3>\n<p>A security issue affects these releases of Ubuntu and its<br \/>\n    derivatives:<\/p>\n<ul>\n<li>Ubuntu 16.04 LTS<\/li>\n<li>Ubuntu 14.04 LTS<\/li>\n<\/ul>\n<h3>Summary<\/h3>\n<p>Several security issues were fixed in JasPer.\n<\/p>\n<h3>Software description<\/h3>\n<ul>\n<li>jasper<br \/>\n    &#8211; Library for manipulating JPEG-2000 files<\/p>\n<\/li>\n<\/ul>\n<h3>Details<\/h3>\n<p>It was discovered that JasPer incorrectly handled certain malformed<br \/>JPEG-2000 image files. If a user or automated system using JasPer were<br \/>tricked into opening a specially crafted image, an attacker could exploit<br \/>this to cause a denial of service or possibly execute code with the<br \/>privileges of the user invoking the program.<\/p>\n<h3>Update instructions<\/h3>\n<p> The problem can be corrected by updating your system to the following<br \/>\npackage version:<\/p>\n<dl>\n<dt>Ubuntu 16.04 LTS:<\/dt>\n<dd>\n    <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jasper\">libjasper1<\/a><br \/>\n    <span><br \/>\n        <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jasper\/1.900.1-debian1-2.4ubuntu1.1\">1.900.1-debian1-2.4ubuntu1.1<\/a><br \/>\n    <\/span>\n  <\/dd>\n<dt>Ubuntu 14.04 LTS:<\/dt>\n<dd>\n    <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jasper\">libjasper1<\/a><br \/>\n    <span><br \/>\n        <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/jasper\/1.900.1-14ubuntu3.4\">1.900.1-14ubuntu3.4<\/a><br \/>\n    <\/span>\n  <\/dd>\n<\/dl>\n<p>To update your system, please follow these instructions:<br \/>\n<a href=\"https:\/\/wiki.ubuntu.com\/Security\/Upgrades\">https:\/\/wiki.ubuntu.com\/Security\/Upgrades<\/a>.\n<\/p>\n<p>In general, a standard system update will make all the necessary changes.<\/p>\n<h3>References<\/h3>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-10249\">CVE-2016-10249<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-10251\">CVE-2016-10251<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-1867\">CVE-2016-1867<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-2089\">CVE-2016-2089<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-8654\">CVE-2016-8654<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-8691\">CVE-2016-8691<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-8692\">CVE-2016-8692<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-8693\">CVE-2016-8693<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-8882\">CVE-2016-8882<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-9560\">CVE-2016-9560<\/a>, <\/p>\n<p>        <a href=\"http:\/\/people.ubuntu.com\/~ubuntu-security\/cve\/CVE-2016-9591\">CVE-2016-9591<\/a><\/p>\n<p>Source: <a href=\"http:\/\/www.ubuntu.com\/usn\/usn-3295-1\/\" target=\"_blank\">USN-3295-1: JasPer vulnerabilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>USN-3295-1: JasPer vulnerabilities Ubuntu Security Notice USN-3295-1 18th May, 2017 jasper vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in JasPer. Software description jasper &#8211; Library for manipulating JPEG-2000 files Details It was discovered that JasPer incorrectly handled certain malformedJPEG-2000 image files. If a user or automated system using JasPer weretricked into opening a specially crafted image, an attacker could exploitthis to cause a denial of service or possibly execute code with theprivileges of the user invoking the program. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libjasper1 1.900.1-debian1-2.4ubuntu1.1 Ubuntu 14.04 LTS: libjasper1 1.900.1-14ubuntu3.4 To update your system, please follow these instructions: https:\/\/wiki.ubuntu.com\/Security\/Upgrades. In general, a standard system update will make all the <a class=\"mh-excerpt-more\" href=\"https:\/\/jirak.net\/wp\/usn-3295-1-jasper-vulnerabilities\/\" title=\"USN-3295-1: JasPer vulnerabilities\">[ more&#8230; ]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[586],"tags":[587],"class_list":["post-16224","post","type-post","status-publish","format-standard","hentry","category-ubuntu-usn","tag-ubuntu-usn"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/16224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/comments?post=16224"}],"version-history":[{"count":1,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/16224\/revisions"}],"predecessor-version":[{"id":16225,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/16224\/revisions\/16225"}],"wp:attachment":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media?parent=16224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/categories?post=16224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/tags?post=16224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}