openSUSE-SU-2019:2279-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2279-1
openSUSE-SU-2019:2279-1
Summary: Security update for jasper
Details: This update for jasper fixes the following issues: Security issues fixed: - CVE-2018-19540: Fixed a heap based overflow in jas_icctxtdesc_input (bsc#1117508). - CVE-2018-19541: Fix heap based overread in jas_image_depalettize (bsc#1117507). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/UJSNBFOOKYKU7PNNS3PPQY4XHQVUNWER/#UJSNBFOOKYKU7PNNS3PPQY4XHQVUNWER, https://bugzilla.suse.com/1117507, https://bugzilla.suse.com/1117508, https://www.suse.com/security/cve/CVE-2018-19540, https://www.suse.com/security/cve/CVE-2018-19541
Affected packages
Package
Name: jasper
Purl: pkg:rpm/opensuse/jasper&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
