Jasper-2.0.24, includes CVE fixes
|Reported by:||Owned by:||Douglas R. Reno|
I just noticed fedora updated to this. http://www.ece.uvic.ca/~frodo/jasper/
Quoting their update report via lwn.net:
New upstream version 2.0.24 with all reported CVE fixes available.
- Mon Jan 25 2021 Josef Ridky <jridky@…> - 2.0.24-1
- New upstream release 2.0.24 (#1905690)
[ 1 ] Bug #1434464 - CVE-2016-9396 CVE-2016-9397 CVE-2016-9398 CVE-2016-9399 CVE-2017-1000050
CVE-2017-13745 CVE-2017-13746 CVE-2017-13747 CVE-2017-13748 CVE-2017-13749 CVE-2017-13750 CVE-2017-13751 CVE-2017-13752 CVE-2017-14132 ... jasper: various flaws [fedora-all]
[ 2 ] Bug #1905202 - CVE-2020-27828 jasper: heap-based buffer overflow in cp_create() in
[ 3 ] Bug #1905690 - jasper-2.0.24 is available
Not all of those are currently listed at NVD, and I suspect 2017-1000050 probably has two zeroes too many, but a random inspection of 2016-9396, 2017-13745, 2017-14132 and 2020-27828 shows those are all rated as High.