Skip to content

Commit

Permalink
package/jasper: security bump to version 2.0.19
Browse files Browse the repository at this point in the history
Fixes the following security issues:
* Fix CVE-2018-9154
  jasper-software/jasper#215
  jasper-software/jasper#166
  jasper-software/jasper#175
  jasper-maint/jasper#8

* Fix CVE-2018-19541
  jasper-software/jasper#199
  jasper-maint/jasper#6

* Fix CVE-2016-9399, CVE-2017-13751
  jasper-maint/jasper#1

* Fix CVE-2018-19540
  jasper-software/jasper#182
  jasper-maint/jasper#22

* Fix CVE-2018-9055
  jasper-maint/jasper#9

* Fix CVE-2017-13748
  jasper-software/jasper#168

* Fix CVE-2017-5503, CVE-2017-5504, CVE-2017-5505
  jasper-maint/jasper#3
  jasper-maint/jasper#4
  jasper-maint/jasper#5
  jasper-software/jasper#88
  jasper-software/jasper#89
  jasper-software/jasper#90

* Fix CVE-2018-9252
  jasper-maint/jasper#16

* Fix CVE-2018-19139
  jasper-maint/jasper#14

* Fix CVE-2018-19543, CVE-2017-9782
  jasper-maint/jasper#13
  jasper-maint/jasper#18
  jasper-software/jasper#140
  jasper-software/jasper#182

* Fix CVE-2018-20570
  jasper-maint/jasper#11
  jasper-software/jasper#191

* Fix CVE-2018-20622
  jasper-maint/jasper#12
  jasper-software/jasper#193

* Fix CVE-2016-9398
  jasper-maint/jasper#10

* Fix CVE-2017-14132
  jasper-maint/jasper#17

* Fix CVE-2017-5499
  jasper-maint/jasper#2
  jasper-software/jasper#63

* Fix CVE-2018-18873
  jasper-maint/jasper#15
  jasper-software/jasper#184

* Fix CVE-2017-13750
  jasper-software/jasper#165
  jasper-software/jasper#174

Furthermore, drop now upstreamed patches and change to the new
jasper-software upstream location.

Signed-off-by: Michael Vetter <jubalh@iodoru.org>
[Peter: reword for security bump]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
  • Loading branch information
jubalh authored and jacmet committed Aug 3, 2020
1 parent 18a6501 commit d0f7b24
Show file tree
Hide file tree
Showing 5 changed files with 3 additions and 91 deletions.
35 changes: 0 additions & 35 deletions package/jasper/0001-verify-data-range-CVE-2018-19541.patch

This file was deleted.

24 changes: 0 additions & 24 deletions package/jasper/0002-check-null-in-jp2_decode-CVE-2018-19542.patch

This file was deleted.

29 changes: 0 additions & 29 deletions package/jasper/0003-test-asclen-CVE-2018-19540.patch

This file was deleted.

2 changes: 1 addition & 1 deletion package/jasper/jasper.hash
@@ -1,3 +1,3 @@
# Locally calculated
sha256 f1d8b90f231184d99968f361884e2054a1714fdbbd9944ba1ae4ebdcc9bbfdb1 jasper-2.0.16.tar.gz
sha256 b9d16162a088617ada36450f2374d72165377cb64b33ed197c200bcfb73ec76c jasper-2.0.19.tar.gz
sha256 4ad1bb42aff888c4403d792e6e2c5f1716d6c279fea70b296333c9d577d30b81 LICENSE
4 changes: 2 additions & 2 deletions package/jasper/jasper.mk
Expand Up @@ -4,8 +4,8 @@
#
################################################################################

JASPER_VERSION = 2.0.16
JASPER_SITE = $(call github,mdadams,jasper,version-$(JASPER_VERSION))
JASPER_VERSION = 2.0.19
JASPER_SITE = $(call github,jasper-software,jasper,version-$(JASPER_VERSION))
JASPER_INSTALL_STAGING = YES
JASPER_LICENSE = JasPer-2.0
JASPER_LICENSE_FILES = LICENSE
Expand Down

0 comments on commit d0f7b24

Please sign in to comment.