Fedora 11 : jasper-1.900.1-13.fc11 (2009-10761)

This script is Copyright (C) 2009-2016 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

- Tue Oct 13 2009 Rex Dieter <rdieter at
fedoraproject.org> - 1.900.1-13

- CVE-2008-3520 jasper: multiple integer overflows in
jas_alloc calls (#461476)

- CVE-2008-3522 jasper: possible buffer overflow in
jas_stream_printf() (#461478)

- Fri Jul 24 2009 Fedora Release Engineering <rel-eng at
lists.fedoraproject.org> - 1.900.1-12

- Rebuilt for
https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

- Sat Jul 18 2009 Rex Dieter <rdieter at
fedoraproject.org> - 1.900.1-11

- FTBFS jasper-1.900.1-10.fc11 (#511743)

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

https://bugzilla.redhat.com/show_bug.cgi?id=461476
https://bugzilla.redhat.com/show_bug.cgi?id=461478
https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
http://www.nessus.org/u?10a4fd62

Solution :

Update the affected jasper package.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.7
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Fedora Local Security Checks

Nessus Plugin ID: 42275 (fedora_2009-10761.nasl)

Bugtraq ID: 31470

CVE ID: CVE-2008-3520
CVE-2008-3522

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now