openSUSE-SU-2020:1517-1
Dashboard / Vulnerabilities / openSUSE-SU-2020:1517-1
openSUSE-SU-2020:1517-1
Summary: Security update for jasper
Details: This update for jasper fixes the following issues: - CVE-2016-9398: Improved patch for already fixed issue (bsc#1010979). - CVE-2016-9399: Fix assert in calcstepsizes (bsc#1010980). - CVE-2017-5499: Validate component depth bit (bsc#1020451). - CVE-2017-5503: Check bounds in jas_seq2d_bindsub() (bsc#1020456). - CVE-2017-5504: Check bounds in jas_seq2d_bindsub() (bsc#1020458). - CVE-2017-5505: Check bounds in jas_seq2d_bindsub() (bsc#1020460). - CVE-2017-14132: Fix heap base overflow in by checking components (bsc#1057152). - CVE-2018-9252: Fix reachable assertion in jpc_abstorelstepsize (bsc#1088278). - CVE-2018-18873: Fix null pointer deref in ras_putdatastd (bsc#1114498). - CVE-2018-19139: Fix mem leaks by registering jpc_unk_destroyparms (bsc#1115637). - CVE-2018-19543, bsc#1045450 CVE-2017-9782: Fix numchans mixup (bsc#1117328). - CVE-2018-20570: Fix heap based buffer over-read in jp2_encode (bsc#1120807). - CVE-2018-20622: Fix memory leak in jas_malloc.c (bsc#1120805). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/ZNYUBLSX2ZSBGFVNDEMDDHDZ2UPLCJR2/, https://bugzilla.suse.com/1010979, https://bugzilla.suse.com/1010980, https://bugzilla.suse.com/1020451, https://bugzilla.suse.com/1020456, https://bugzilla.suse.com/1020458, https://bugzilla.suse.com/1020460, https://bugzilla.suse.com/1045450, https://bugzilla.suse.com/1057152, https://bugzilla.suse.com/1088278, https://bugzilla.suse.com/1114498, https://bugzilla.suse.com/1115637, https://bugzilla.suse.com/1117328, https://bugzilla.suse.com/1120805, https://bugzilla.suse.com/1120807, https://www.suse.com/security/cve/CVE-2016-9398, https://www.suse.com/security/cve/CVE-2016-9399, https://www.suse.com/security/cve/CVE-2017-14132, https://www.suse.com/security/cve/CVE-2017-5499, https://www.suse.com/security/cve/CVE-2017-5503, https://www.suse.com/security/cve/CVE-2017-5504, https://www.suse.com/security/cve/CVE-2017-5505, https://www.suse.com/security/cve/CVE-2017-9782, https://www.suse.com/security/cve/CVE-2018-18873, https://www.suse.com/security/cve/CVE-2018-19139, https://www.suse.com/security/cve/CVE-2018-19543, https://www.suse.com/security/cve/CVE-2018-20570, https://www.suse.com/security/cve/CVE-2018-20622, https://www.suse.com/security/cve/CVE-2018-9252
Affected packages
Package
Name: jasper
Purl: pkg:rpm/opensuse/jasper&distro=openSUSE%20Leap%2015.1
Affected ranges
Type: ECOSYSTEM
Events:
