Hide Forgot
Null pointer dereference vulnerability in jp2_colr_destroy in jp2_cod.c was found. This is incomplete fix for CVE-2016-8887. CVE request: http://seclists.org/oss-sec/2016/q4/218 Upstream patch: https://github.com/mdadams/jasper/commit/bdfe95a6e81ffb4b2fad31a76b57943695beed20
Created mingw-jasper tracking bugs for this issue: Affects: fedora-all [bug 1388874] Affects: epel-7 [bug 1388876]
Created jasper tracking bugs for this issue: Affects: fedora-all [bug 1388873] Affects: epel-5 [bug 1388875]
Merging with the original report, as we have no real need for separate bug. *** This bug has been marked as a duplicate of bug 1388828 ***
This was assigned CVE-2016-10250: http://seclists.org/oss-sec/2017/q1/608