SUSE-SU-2019:2444-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2444-1
SUSE-SU-2019:2444-1
Summary: Security update for djvulibre
Details: This update for djvulibre fixes the following issues: Security issues fixed: - CVE-2019-15142: Fixed heap-based buffer over-read (bsc#1146702). - CVE-2019-15143: Fixed resource exhaustion caused by corrupted image files (bsc#1146569). - CVE-2019-15144: Fixed denial-of-service caused by crafted PBM image files (bsc#1146571). - CVE-2019-15145: Fixed out-of-bounds read caused by corrupted JB2 image files (bsc#1146572). - Fixed segfault when libtiff encounters corrupted TIFF (upstream issue #295).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192444-1/, https://bugzilla.suse.com/1146569, https://bugzilla.suse.com/1146571, https://bugzilla.suse.com/1146572, https://bugzilla.suse.com/1146702, https://www.suse.com/security/cve/CVE-2019-15142, https://www.suse.com/security/cve/CVE-2019-15143, https://www.suse.com/security/cve/CVE-2019-15144, https://www.suse.com/security/cve/CVE-2019-15145
Affected packages
Package
Name: djvulibre
Purl: pkg:rpm/suse/djvulibre&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
