[CLSA-2026:1778219363] jasper: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-08 05:49:29 UTC
Description:
- Add Amazon Linux 2 ELS support (mirrors centos7els branch with .amzn2 dist via .0/.1 leapfrog over stock 1.900.1-33.amzn2.0.1) - Import CVE-2020-27828 patch from amzn2 stock SRPM (out-of-bounds write in jpc encoder; jasper-2.0.14-CVE-2020-27828.patch) - Import CVE-2021-3443 patch from amzn2 stock SRPM (NULL pointer dereference in JP2 component reference handling) - Import CVE-2021-3467 patch from amzn2 stock SRPM (NULL pointer dereference in CDEF box channel reference handling)
Updated packages:
  • jasper-1.900.1-33.amzn2.0.1.tuxcare.els6.x86_64.rpm
    sha:bad3aca027082006e525783314b37d2af7f22d399eb187654d6eeb846908d0a3
  • jasper-devel-1.900.1-33.amzn2.0.1.tuxcare.els6.x86_64.rpm
    sha:7539d12013f4ac825953897c084afa8fbed3c62939c49cb4b56a98bb25885012
  • jasper-libs-1.900.1-33.amzn2.0.1.tuxcare.els6.i686.rpm
    sha:3e6e43b40a8805168ebcd780b5eb43917a0efe762ff95fe0845b5dcb7376d3da
  • jasper-libs-1.900.1-33.amzn2.0.1.tuxcare.els6.x86_64.rpm
    sha:ba797dd0ec660e0345258c07d04097e74812cff1a74eed79883aa5ed5ab797f7
  • jasper-utils-1.900.1-33.amzn2.0.1.tuxcare.els6.x86_64.rpm
    sha:dc0744a340d4c9a581591b905b99e05e62540da315ae5bd4bc3ea7aa7a2cb907
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.