Описание
Security update for jasper
This update for jasper fixes the following issues:
Security issues fixed:
- CVE-2016-9600: Null Pointer Dereference due to missing check for UNKNOWN color space in JP2 encoder (bsc#1018088)
- CVE-2016-10251: Use of uninitialized value in jpc_pi_nextcprl (jpc_t2cod.c) (bsc#1029497)
- CVE-2017-5498: left-shift undefined behaviour (bsc#1020353)
- CVE-2017-6850: NULL pointer dereference in jp2_cdef_destroy (jp2_cod.c) (bsc#1021868)
- CVE-2016-9583: Out of bounds heap read in jpc_pi_nextpcrl() (bsc#1015400)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP1
SUSE Linux Enterprise Software Development Kit 12 SP2
Ссылки
- Link for SUSE-SU-2017:0953-1
- E-Mail link for SUSE-SU-2017:0953-1
- SUSE Security Ratings
- SUSE Bug 1015400
- SUSE Bug 1018088
- SUSE Bug 1020353
- SUSE Bug 1021868
- SUSE Bug 1029497
- SUSE CVE CVE-2016-10251 page
- SUSE CVE CVE-2016-9583 page
- SUSE CVE CVE-2016-9600 page
- SUSE CVE CVE-2017-5498 page
- SUSE CVE CVE-2017-6850 page
Описание
Integer overflow in the jpc_pi_nextcprl function in jpc_t2cod.c in JasPer before 1.900.20 allows remote attackers to have unspecified impact via a crafted file, which triggers use of an uninitialized value.
Затронутые продукты
Ссылки
- CVE-2016-10251
- SUSE Bug 1029497
- SUSE Bug 1178702
Описание
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
Затронутые продукты
Ссылки
- CVE-2016-9583
- SUSE Bug 1015400
- SUSE Bug 1178702
Описание
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.
Затронутые продукты
Ссылки
- CVE-2016-9600
- SUSE Bug 1018088
- SUSE Bug 1178702
Описание
libjasper/include/jasper/jas_math.h in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
Затронутые продукты
Ссылки
- CVE-2017-5498
- SUSE Bug 1020353
- SUSE Bug 1020451
- SUSE Bug 1020456
- SUSE Bug 1020460
- SUSE Bug 1178702
Описание
The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
Затронутые продукты
Ссылки
- CVE-2017-6850
- SUSE Bug 1021868
- SUSE Bug 1178702