[Bug 240397] New: CVE-2007-2721: jasper DoS, heap corruption
by Red Hat Bugzilla
Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=240397
Summary: CVE-2007-2721: jasper DoS, heap corruption
Product: Fedora Extras
Version: fc6
Platform: All
OS/Version: Linux
Status: NEW
Severity: medium
Priority: medium
Component: jasper
AssignedTo: rdieter(a)math.unl.edu
ReportedBy: ville.skytta(a)iki.fi
QAContact: extras-qa(a)fedoraproject.org
CC: fedora-security-list(a)redhat.com
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2721
"The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000
library (libjasper) before 1.900 allows remote user-assisted attackers to cause
a denial of service (crash) and possibly corrupt the heap via malformed image
files, as originally demonstrated using imagemagick convert."
Appears to affect 1.900.1 too.
--
Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.
14 years, 9 months
ARP handler Inspection tool released
by Andrea Di Pasquale
ArpON (Arp handler inspectiON) is a portable Arp handler.
It Detects and Blocks all ARP Poisoning/Spoofing attacks with
Static Arp Inspection (SARPI) and Dynamic Arp Inspection (DARPI)
approach on switched/hubbed LAN with/without DHCP protocol.
Important to note, it doesn't compromise the ARP protocol performances.
I need testing and code revision, thank you.
The link to project's documentation is:
http://arpon.sourceforge.net/about.html
The link to the project is:
http://arpon.sourceforge.net
15 years