Source: jasper Version: 1.900.1-13 Severity: grave Tags: security upstream Justification: user security hole
Hi, the following vulnerability was published for jasper. CVE-2016-8690[0]: SEGV on unknown address ... bmp_getdata ... bmp_dec.c If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2016-8690 [1] https://blogs.gentoo.org/ago/2016/10/16/jasper-two-null-pointer-dereference-in-bmp_getdata-bmp_dec-c/ Regards, Salvatore