openSUSE-SU-2019:2217-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2217-1
openSUSE-SU-2019:2217-1
Summary: Security update for djvulibre
Details: This update for djvulibre fixes the following issues: Security issues fixed: - CVE-2019-15142: Fixed heap-based buffer over-read (bsc#1146702). - CVE-2019-15143: Fixed resource exhaustion caused by corrupted image files (bsc#1146569). - CVE-2019-15144: Fixed denial-of-service caused by crafted PBM image files (bsc#1146571). - CVE-2019-15145: Fixed out-of-bounds read caused by corrupted JB2 image files (bsc#1146572). - Fixed segfault when libtiff encounters corrupted TIFF (upstream issue #295). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/IH4MQKYJLC6RE2GZDHVFRWARHBFRQAP4/#IH4MQKYJLC6RE2GZDHVFRWARHBFRQAP4, https://bugzilla.suse.com/1146569, https://bugzilla.suse.com/1146571, https://bugzilla.suse.com/1146572, https://bugzilla.suse.com/1146702, https://www.suse.com/security/cve/CVE-2019-15142, https://www.suse.com/security/cve/CVE-2019-15143, https://www.suse.com/security/cve/CVE-2019-15144, https://www.suse.com/security/cve/CVE-2019-15145
Affected packages
Package
Name: djvulibre
Purl: pkg:rpm/opensuse/djvulibre&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
