[Secure-testing-team] Bug#841110: jasper: CVE-2016-8693

Salvatore Bonaccorso carnil at debian.org
Mon Oct 17 18:01:52 UTC 2016


Source: jasper
Version: 1.900.1-13
Severity: grave
Tags: security upstream

Hi,

the following vulnerability was published for jasper.

CVE-2016-8693[0]:
attempting double-free ... mem_close ... jas_stream.c

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-8693
[1] https://blogs.gentoo.org/ago/2016/10/16/jasper-double-free-in-mem_close-jas_stream-c/

Regards,
Salvatore



More information about the Secure-testing-team mailing list