SUSE-SU-2017:1916-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1916-1
SUSE-SU-2017:1916-1
Summary: Security update for jasper
Details: This update for jasper fixes the following issues: Security issues fixed: - CVE-2016-9262: Multiple integer overflows in the jas_realloc function in base/jas_malloc.c and mem_resize function in base/jas_stream.c allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities. (bsc#1009994) - CVE-2016-9388: The ras_getcmap function in ras_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010975) - CVE-2016-9389: The jpc_irct and jpc_iict functions in jpc_mct.c allow remote attackers to cause a denial of service (assertion failure). (bsc#1010968) - CVE-2016-9390: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010774) - CVE-2016-9391: The jpc_bitstream_getbits function in jpc_bs.c allows remote attackers to cause a denial of service (assertion failure) via a very large integer. (bsc#1010782) - CVE-2017-1000050: The jp2_encode function in jp2_enc.c allows remote attackers to cause a denial of service. (bsc#1047958) CVEs already fixed with previous update: - CVE-2016-9392: The calcstepsizes function in jpc_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010757) - CVE-2016-9393: The jpc_pi_nextrpcl function in jpc_t2cod.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010766) - CVE-2016-9394: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010756)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171916-1/, https://bugzilla.suse.com/1009994, https://bugzilla.suse.com/1010756, https://bugzilla.suse.com/1010757, https://bugzilla.suse.com/1010766, https://bugzilla.suse.com/1010774, https://bugzilla.suse.com/1010782, https://bugzilla.suse.com/1010968, https://bugzilla.suse.com/1010975, https://bugzilla.suse.com/1047958, https://www.suse.com/security/cve/CVE-2016-9262, https://www.suse.com/security/cve/CVE-2016-9388, https://www.suse.com/security/cve/CVE-2016-9389, https://www.suse.com/security/cve/CVE-2016-9390, https://www.suse.com/security/cve/CVE-2016-9391, https://www.suse.com/security/cve/CVE-2016-9392, https://www.suse.com/security/cve/CVE-2016-9393, https://www.suse.com/security/cve/CVE-2016-9394, https://www.suse.com/security/cve/CVE-2017-1000050
Affected packages
Package
Name: jasper
Purl: pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
