========================================================================= Ubuntu Security Notice USN-4688-1 January 11, 2021 jasper vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in JasPer. Software Description: - jasper: Library for manipulating JPEG-2000 files Details: It was discovered that Jasper incorrectly certain files. An attacker could possibly use this issue to cause a crash. (CVE-2018-18873) It was discovered that Jasper incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-19542) It was discovered that Jasper incorrectly handled certain JPC encoders. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-27828) It was discovered that Jasper incorrectly handled certain images. An attacker could possibly use this issue to expose sensitive information or cause a crash. (CVE-2017-9782) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libjasper1 1.900.1-debian1-2.4ubuntu1.3 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/4688-1 CVE-2017-9782, CVE-2018-18873, CVE-2018-19542, CVE-2020-27828 Package Information: https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.3