shield
Security update for jasper
slessp4-jasper-13215
This update for jasper fixes the following issues: Security issues fixed: - CVE-2016-9262: Multiple integer overflows in the jas_realloc function in base/jas_malloc.c and mem_resize function in base/jas_stream.c allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities. (bsc#1009994) - CVE-2016-9388: The ras_getcmap function in ras_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010975) - CVE-2016-9389: The jpc_irct and jpc_iict functions in jpc_mct.c allow remote attackers to cause a denial of service (assertion failure). (bsc#1010968) - CVE-2016-9390: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010774) - CVE-2016-9391: The jpc_bitstream_getbits function in jpc_bs.c allows remote attackers to cause a denial of service (assertion failure) via a very large integer. (bsc#1010782) - CVE-2017-1000050: The jp2_encode function in jp2_enc.c allows remote attackers to cause a denial of service. (bsc#1047958) CVEs already fixed with previous update: - CVE-2016-9392: The calcstepsizes function in jpc_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010757) - CVE-2016-9393: The jpc_pi_nextrpcl function in jpc_t2cod.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010766) - CVE-2016-9394: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010756)
-
Release DateJul 19 2017
-
ReferencesBugzilla: 1010766, 1047958, 1010757, 1010756, 1010774, 1009994, 1010968, 1010782, 1010975
CVEs: CVE-2017-1000050, CVE-2016-9389, CVE-2016-9388, CVE-2016-9392, CVE-2016-9393, CVE-2016-9390, CVE-2016-9391, CVE-2016-9262, CVE-2016-9394 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server for SAP All-in-One 11.4 x86_64
-
Packagesjasper
An Implementation of the JPEG-2000 Standard, Part 1libjasper1.900.14-134.33.3.1 lock src
JPEG-2000 librarylibjasper-32bit1.900.14-134.33.3.1 lock rpm
JPEG-2000 library1.900.14-134.33.3.1 lock rpm
SUSE Linux Enterprise Server 11.4 s390x
-
Packagesjasper
An Implementation of the JPEG-2000 Standard, Part 1libjasper1.900.14-134.33.3.1 lock src
JPEG-2000 librarylibjasper-32bit1.900.14-134.33.3.1 lock rpm
JPEG-2000 library1.900.14-134.33.3.1 lock rpm
SUSE Linux Enterprise Server for SAP Applications 11.4 ppc64
-
Packagesjasper
An Implementation of the JPEG-2000 Standard, Part 1libjasper1.900.14-134.33.3.1 lock src
JPEG-2000 librarylibjasper-32bit1.900.14-134.33.3.1 lock rpm
JPEG-2000 library1.900.14-134.33.3.1 lock rpm
SUSE Linux Enterprise Server 11.4 ia64
-
Packagesjasper
An Implementation of the JPEG-2000 Standard, Part 1libjasper1.900.14-134.33.3.1 lock src
JPEG-2000 librarylibjasper-x861.900.14-134.33.3.1 lock rpm
JPEG-2000 library1.900.14-134.33.3.1 lock rpm
SUSE Linux Enterprise Server 11.4 i586
-
Packages