SUSE-SU-2020:2690-1
Dashboard / Vulnerabilities / SUSE-SU-2020:2690-1
SUSE-SU-2020:2690-1
Summary: Security update for jasper
Details: This update for jasper fixes the following issues: - CVE-2016-9398: Improved patch for already fixed issue (bsc#1010979). - CVE-2016-9399: Fix assert in calcstepsizes (bsc#1010980). - CVE-2016-9397: Fix assert in jpc_dequantize (bsc#1010786). - CVE-2016-9557: Fix signed integer overflow (bsc#1011829). - CVE-2017-5499: Validate component depth bit (bsc#1020451). - CVE-2017-5503: Check bounds in jas_seq2d_bindsub() (bsc#1020456). - CVE-2017-5504: Check bounds in jas_seq2d_bindsub() (bsc#1020458). - CVE-2017-5505: Check bounds in jas_seq2d_bindsub() (bsc#1020460). - CVE-2017-14132: Fix heap base overflow in by checking components (bsc#1057152). - CVE-2018-9154: Fixed a potential denial of service in jpc_dec_process_sot() (bsc#1092115). - CVE-2018-9252: Fix reachable assertion in jpc_abstorelstepsize (bsc#1088278). - CVE-2018-18873: Fix null pointer deref in ras_putdatastd (bsc#1114498). - CVE-2018-19139: Fix mem leaks by registering jpc_unk_destroyparms (bsc#1115637). - CVE-2018-19543, bsc#1045450 CVE-2017-9782: Fix numchans mixup (bsc#1117328). - CVE-2018-20570: Fix heap based buffer over-read in jp2_encode (bsc#1120807). - CVE-2018-20622: Fix memory leak in jas_malloc.c (bsc#1120805).
References: https://www.suse.com/support/update/announcement/2020/suse-su-20202690-1/, https://bugzilla.suse.com/1010786, https://bugzilla.suse.com/1010979, https://bugzilla.suse.com/1010980, https://bugzilla.suse.com/1011829, https://bugzilla.suse.com/1020451, https://bugzilla.suse.com/1020456, https://bugzilla.suse.com/1020458, https://bugzilla.suse.com/1020460, https://bugzilla.suse.com/1045450, https://bugzilla.suse.com/1057152, https://bugzilla.suse.com/1088278, https://bugzilla.suse.com/1092115, https://bugzilla.suse.com/1114498, https://bugzilla.suse.com/1115637, https://bugzilla.suse.com/1117328, https://bugzilla.suse.com/1120805, https://bugzilla.suse.com/1120807, https://www.suse.com/security/cve/CVE-2016-9397, https://www.suse.com/security/cve/CVE-2016-9398, https://www.suse.com/security/cve/CVE-2016-9399, https://www.suse.com/security/cve/CVE-2016-9557, https://www.suse.com/security/cve/CVE-2017-14132, https://www.suse.com/security/cve/CVE-2017-5499, https://www.suse.com/security/cve/CVE-2017-5503, https://www.suse.com/security/cve/CVE-2017-5504, https://www.suse.com/security/cve/CVE-2017-5505, https://www.suse.com/security/cve/CVE-2017-9782, https://www.suse.com/security/cve/CVE-2018-18873, https://www.suse.com/security/cve/CVE-2018-19139, https://www.suse.com/security/cve/CVE-2018-19543, https://www.suse.com/security/cve/CVE-2018-20570, https://www.suse.com/security/cve/CVE-2018-20622, https://www.suse.com/security/cve/CVE-2018-9154, https://www.suse.com/security/cve/CVE-2018-9252
Affected packages
Package
Name: jasper
Purl: pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
