[CLSA-2026:1778227041] jasper: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-05-08 11:49:13 UTC
Description:
- Add Amazon Linux 2 ELS support (mirrors centos7els branch with .amzn2 dist via / leapfrog over stock 1.900.1-33.amzn2.0.1) - Import CVE-2020-27828 patch from amzn2 stock SRPM (out-of-bounds write in jpc encoder; jasper-2.0.14-CVE-2020-27828.patch) - Import CVE-2021-3443 patch from amzn2 stock SRPM (NULL pointer dereference in JP2 component reference handling) - Import CVE-2021-3467 patch from amzn2 stock SRPM (NULL pointer dereference in CDEF box channel reference handling)
Updated packages:
  • jasper-1.900.1-33.el7.tuxcare.els6.x86_64.rpm
    sha:291f42c749331ebae7de706e30b873b003a38748973b2140213d7d78fde88637
  • jasper-devel-1.900.1-33.el7.tuxcare.els6.i686.rpm
    sha:5496f9fe2102ae22435cfba99b2c9f02aec78d2cb0dfbd792db0ce8d94f55aaa
  • jasper-devel-1.900.1-33.el7.tuxcare.els6.x86_64.rpm
    sha:8e9a229446ec9f9d55e4baf3aba2e85d73d3869deb871917531dea66fdb19ca6
  • jasper-libs-1.900.1-33.el7.tuxcare.els6.i686.rpm
    sha:f7e7322b2b8e6b7e0d559837b1499a198120e6e11ad3e205e69d3590395a0329
  • jasper-libs-1.900.1-33.el7.tuxcare.els6.x86_64.rpm
    sha:7af50d52bd995c622a44286780717493dbb34427daae2e6dbd4d78b5d15a05e7
  • jasper-utils-1.900.1-33.el7.tuxcare.els6.x86_64.rpm
    sha:1c12db7a5999ae7dc0b1e41469358733ffb87395659af049622f34f95a1472a0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.