CVE-2014-9029

Publication date 4 December 2014

Last updated 24 July 2024


Ubuntu priority

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

Status

Package Ubuntu Release Status
ghostscript 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid
Fixed 8.71.dfsg.1-0ubuntu5.6
jasper 14.10 utopic
Fixed 1.900.1-debian1-2ubuntu0.1
14.04 LTS trusty
Fixed 1.900.1-14ubuntu3.1
12.04 LTS precise
Fixed 1.900.1-13ubuntu0.1
10.04 LTS lucid Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-2434-2
    • Ghostscript vulnerability
    • 8 December 2014

Other references