Hide Forgot
Null pointer dereference vulnerability in bmp_getdata in bmp_dec.c was found. Upstream patch: https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698 CVE assignment: http://seclists.org/oss-sec/2016/q4/213
Created mingw-jasper tracking bugs for this issue: Affects: fedora-all [bug 1388874] Affects: epel-7 [bug 1388876]
Created jasper tracking bugs for this issue: Affects: fedora-all [bug 1388873] Affects: epel-5 [bug 1388875]
Both CVEs here - CVE-2016-8884 CVE-2016-8885 - were assigned to the same issue for which CVE-2016-8690 was originally assigned and which was not addressed in the original patch. I'm going move these additional CVEs to the bug used to track CVE-2016-8690, as it's really a single issue with 3 CVE ids. *** This bug has been marked as a duplicate of bug 1385499 ***