Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2513-1

Опубликовано: 02 окт. 2019
Источник: suse-cvrf

Описание

Security update for jasper

This update for jasper fixes the following issues:

Security issues fixed:

  • CVE-2018-19540: Fixed a heap based overflow in jas_icctxtdesc_input (bsc#1117508).
  • CVE-2018-19541: Fix heap based overread in jas_image_depalettize (bsc#1117507).
  • CVE-2018-19542: Fixed a denial of service in jp2_decode (bsc#1117505).
  • CVE-2018-19539: Fixed a denial of service in jas_image_readcmpt (bsc#1117511).
  • CVE-2016-9396: Fixed a denial of service in jpc_cox_getcompparms (bsc#1010783).

Список пакетов

Image SLES12-SP4-SAP-Azure
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-EC2-HVM
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-GCE
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-GCE-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-OCI-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-Azure-SAP-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-Azure-SAP-On-Demand
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-EC2-SAP-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-EC2-SAP-On-Demand
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-GCE-SAP-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-GCE-SAP-On-Demand
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libjasper1-1.900.14-195.15.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libjasper1-1.900.14-195.15.1
SUSE Linux Enterprise Desktop 12 SP4
libjasper1-1.900.14-195.15.1
libjasper1-32bit-1.900.14-195.15.1
SUSE Linux Enterprise Server 12 SP4
libjasper1-1.900.14-195.15.1
libjasper1-32bit-1.900.14-195.15.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libjasper1-1.900.14-195.15.1
libjasper1-32bit-1.900.14-195.15.1
SUSE Linux Enterprise Software Development Kit 12 SP4
libjasper-devel-1.900.14-195.15.1

Описание

The JPC_NOMINALGAIN function in jpc/jpc_t1cod.c in JasPer through 2.0.12 allows remote attackers to cause a denial of service (JPC_COX_RFT assertion failure) via unspecified vectors.


Затронутые продукты
Image SLES12-SP4-SAP-Azure-BYOS:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure:libjasper1-1.900.14-195.15.1

Ссылки

Описание

An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.


Затронутые продукты
Image SLES12-SP4-SAP-Azure-BYOS:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure:libjasper1-1.900.14-195.15.1

Ссылки

Описание

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer overflow of size 1 in the function jas_icctxtdesc_input in libjasper/base/jas_icc.c.


Затронутые продукты
Image SLES12-SP4-SAP-Azure-BYOS:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure:libjasper1-1.900.14-195.15.1

Ссылки

Описание

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer over-read of size 8 in the function jas_image_depalettize in libjasper/base/jas_image.c.


Затронутые продукты
Image SLES12-SP4-SAP-Azure-BYOS:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure:libjasper1-1.900.14-195.15.1

Ссылки

Описание

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.


Затронутые продукты
Image SLES12-SP4-SAP-Azure-BYOS:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libjasper1-1.900.14-195.15.1
Image SLES12-SP4-SAP-Azure:libjasper1-1.900.14-195.15.1

Ссылки