[Buildroot] [PATCH 1/1] package/jasper: security bump version to 2.0.25
Peter Korsgaard
peter at korsgaard.com
Wed Feb 17 06:36:30 UTC 2021
>>>>> "Michael" == Michael Vetter <jubalh at iodoru.org> writes:
> Changes:
> * Fix memory-related bugs in the JPEG-2000 codec resulting from
> attempting to decode invalid code streams. (#264, #265)
> This fix is associated with CVE-2021-26926 and CVE-2021-26927.
> * Fix wrong return value under some compilers (#260)
> * Fix CVE-2021-3272 heap buffer overflow in jp2_decode (#259)
> Signed-off-by: Michael Vetter <jubalh at iodoru.org>
Committed to 2020.02.x and 2020.11.x, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list