[Buildroot] [PATCH 1/1] package/jasper: security bump version to 2.0.25
Peter Korsgaard
peter at korsgaard.com
Mon Feb 15 21:50:21 UTC 2021
>>>>> "Michael" == Michael Vetter <jubalh at iodoru.org> writes:
> Changes:
> * Fix memory-related bugs in the JPEG-2000 codec resulting from
> attempting to decode invalid code streams. (#264, #265)
> This fix is associated with CVE-2021-26926 and CVE-2021-26927.
> * Fix wrong return value under some compilers (#260)
> * Fix CVE-2021-3272 heap buffer overflow in jp2_decode (#259)
> Signed-off-by: Michael Vetter <jubalh at iodoru.org>
Committed, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list