Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2279-1

Опубликовано: 07 окт. 2019
Источник: suse-cvrf

Описание

Security update for jasper

This update for jasper fixes the following issues:

Security issues fixed:

  • CVE-2018-19540: Fixed a heap based overflow in jas_icctxtdesc_input (bsc#1117508).
  • CVE-2018-19541: Fix heap based overread in jas_image_depalettize (bsc#1117507).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
jasper-2.0.14-lp150.2.6.1
libjasper-devel-2.0.14-lp150.2.6.1
libjasper4-2.0.14-lp150.2.6.1
libjasper4-32bit-2.0.14-lp150.2.6.1

Описание

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer overflow of size 1 in the function jas_icctxtdesc_input in libjasper/base/jas_icc.c.


Затронутые продукты
openSUSE Leap 15.0:jasper-2.0.14-lp150.2.6.1
openSUSE Leap 15.0:libjasper-devel-2.0.14-lp150.2.6.1
openSUSE Leap 15.0:libjasper4-2.0.14-lp150.2.6.1
openSUSE Leap 15.0:libjasper4-32bit-2.0.14-lp150.2.6.1

Ссылки

Описание

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer over-read of size 8 in the function jas_image_depalettize in libjasper/base/jas_image.c.


Затронутые продукты
openSUSE Leap 15.0:jasper-2.0.14-lp150.2.6.1
openSUSE Leap 15.0:libjasper-devel-2.0.14-lp150.2.6.1
openSUSE Leap 15.0:libjasper4-2.0.14-lp150.2.6.1
openSUSE Leap 15.0:libjasper4-32bit-2.0.14-lp150.2.6.1

Ссылки
Уязвимость openSUSE-SU-2019:2279-1