jasper: security bump to version 1.900.22
authorBaruch Siach <baruch@tkos.co.il>
Thu, 10 Nov 2016 17:54:39 +0000 (19:54 +0200)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Fri, 11 Nov 2016 14:07:43 +0000 (15:07 +0100)
commit7a21e6e9e3095197267d11c0844e94d648d5f379
treebf738cd2fc88dcd3981de078adc0c5f88a70af34
parent4f04be1659f186765f506c68f5bfbf6845fc40dc
jasper: security bump to version 1.900.22

Fixes:
CVE-2016-8693: Double free vulnerability in mem_close
CVE-2016-8692: Divide by zero in jpc_dec_process_siz
CVE-2016-8691: Divide by zero in jpc_dec_process_siz
CVE-2016-8690: Null pointer dereference in bmp_getdata triggered by crafted
BMP image
CVE-2016-2089: matrix rows_ NULL pointer dereference in jas_matrix_clip()
CVE-2016-8886: memory allocation failure in jas_malloc
CVE-2016-8887: Null pointer dereference in jp2_colr_destroy
CVE-2016-8884, CVE-2016-8885: Null pointer dereference in bmp_getdata
(incomplete fix for CVE-2016-8690)
CVE-2016-8880: Heap buffer overflow in jpc_dec_cp_setfromcox()
CVE-2016-8881: Heap buffer overflow in jpc_getuint16()
CVE-2016-8882: Null pointer access in jpc_pi_destroy
CVE-2016-8883: Assert in jpc_dec_tiledecode()

Drop upstream patches.

Change SITE to the official download location, since the current one does not
have the updated version. Unfortunately, the official site only offers tar.gz.

Fix license. It is "based on the MIT license", but not exactly the same
(http://www.ece.uvic.ca/~frodo/jasper/; under "Legal Issues").

Drop autoreconf; the autotools version has been updated since commit
324ccec90d (jasper: autoreconf to fix rpath issue) that introduced it.

Cc: Maxime Hadjinlian <maxime.hadjinlian@gmail.com>
Signed-off-by: Baruch Siach <baruch@tkos.co.il>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
14 files changed:
package/jasper/0001-fix-CVE-2014-9029.patch [deleted file]
package/jasper/0002-fix-CVE-2014-8138.patch [deleted file]
package/jasper/0003-fix-CVE-2014-8137-1.patch [deleted file]
package/jasper/0004-fix-CVE-2014-8137-2.patch [deleted file]
package/jasper/0005-fix-CVE-2014-8157.patch [deleted file]
package/jasper/0006-fix-CVE-2014-8158.patch [deleted file]
package/jasper/0007-preserve-cflags.patch [deleted file]
package/jasper/0008-fix-CVE-2016-2116.patch [deleted file]
package/jasper/0009-fix-CVE-2016-1577.patch [deleted file]
package/jasper/0010-fix-CVE-2016-1867.patch [deleted file]
package/jasper/0011-fix-CVE-2015-5221.patch [deleted file]
package/jasper/0012-fix-CVE-2015-5203.patch [deleted file]
package/jasper/jasper.hash
package/jasper/jasper.mk