This bug was fixed in the package jasper - 1.900.1-13ubuntu0.3 --------------- jasper (1.900.1-13ubuntu0.3) precise-security; urgency=medium
* SECURITY UPDATE: Denial of service or possible code execution via crafted ICC color profile (LP: #1547865) - debian/patches/09-CVE-2016-1577.patch: Prevent double-free in src/libjasper/base/jas_icc.c - CVE-2016-1577 * SECURITY UPDATE: Denial of service via resource exhaustion via crafted ICC color profile - debian/patches/10-CVE-2016-2116.patch: Prevent memory leak in src/libjasper/base/jas_icc.c - CVE-2016-2116 -- Tyler Hicks <tyhi...@canonical.com> Fri, 26 Feb 2016 00:07:11 -0600 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1547865 Title: Double free in libjasper jas_icc.c To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/jasper/+bug/1547865/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs