Articles / Ubuntu: New JasPer packages...

Ubuntu: New JasPer packages fix security vulnerabilities

Jonathan Foote discovered that JasPer incorrectly handled certain malformed JPEG-2000 image files. If a user were tricked into opening a specially crafted JPEG-2000 image file, a remote attacker could cause JasPer to crash or possibly execute arbitrary code with user privileges. Updated packages are available from security.ubuntu.com.

==========================================================================
Ubuntu Security Notice USN-1315-1
December 20, 2011

jasper vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

JasPer could be made to crash or run programs as your login if it opened a
specially crafted file.

Software Description:
- jasper: Library for manipulating JPEG-2000 files

Details:

Jonathan Foote discovered that JasPer incorrectly handled certain malformed
JPEG-2000 image files. If a user were tricked into opening a specially
crafted JPEG-2000 image file, a remote attacker could cause JasPer to crash
or possibly execute arbitrary code with user privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
 libjasper1                      1.900.1-7ubuntu2.11.10.1

Ubuntu 11.04:
 libjasper1                      1.900.1-7ubuntu2.11.04.1

Ubuntu 10.10:
 libjasper1                      1.900.1-7ubuntu0.10.10.1

Ubuntu 10.04 LTS:
 libjasper1                      1.900.1-7ubuntu0.10.04.1

In general, a standard system update will make all the necessary changes.

References:
 http://www.ubuntu.com/usn/usn-1315-1
 CVE-2011-4516, CVE-2011-4517

Package Information:
 https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu2.11.10.1
 https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu2.11.04.1
 https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu0.10.10.1
 https://launchpad.net/ubuntu/+source/jasper/1.900.1-7ubuntu0.10.04.1
Screenshot

Project Spotlight

Java Gearman Service

An application framework that farms work out to machines better suited to do the work.

Screenshot

Project Spotlight

GoogleSitesAnt

An Ant task for manipulating Google Sites pages.