Описание
Security update for jasper
This update for jasper fixes the following issues:
- CVE-2016-8654: Heap-based buffer overflow in QMFB code in JPC codec. (bsc#1012530)
- CVE-2016-9395: Invalid jasper files could lead to abort of the library caused by attacker provided image. (bsc#1010977)
- CVE-2016-9398: Invalid jasper files could lead to abort of the library caused by attacker provided image. (bsc#1010979)
- CVE-2016-9560: Stack-based buffer overflow in jpc_tsfb_getbands2. (bsc#1011830)
- CVE-2016-9591: Use-after-free on heap in jas_matrix_destroy. (bsc#1015993)
This update was imported from the SUSE:SLE-12:Update update project.
Список пакетов
openSUSE Leap 42.1
openSUSE Leap 42.2
Ссылки
- E-Mail link for openSUSE-SU-2017:0101-1
- SUSE Security Ratings
Описание
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
Затронутые продукты
Ссылки
- CVE-2016-8654
- SUSE Bug 1012530
- SUSE Bug 1178702
Описание
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
Затронутые продукты
Ссылки
- CVE-2016-9395
- SUSE Bug 1010977
- SUSE Bug 1178702
Описание
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
Затронутые продукты
Ссылки
- CVE-2016-9398
- SUSE Bug 1010979
- SUSE Bug 1178702
Описание
Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer 1.900.26, 1.900.27, 1.900.28, 1.900.29 and 1.900.30 allows remote attackers to have unspecified impact via a crafted image.
Затронутые продукты
Ссылки
- CVE-2016-9560
- SUSE Bug 1011830
- SUSE Bug 1178702
Описание
JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer.
Затронутые продукты
Ссылки
- CVE-2016-9591
- SUSE Bug 1015993
- SUSE Bug 1178702