Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE 11.4 Important: 2011:1328-1 jasper Heap Overflow Fix

opensuse
Calendar Grey December 16, 2011
Dist Opensuse Esm H88
Important enhancement for openSUSE addressing JPEG2000 buffer overflow vulnerabilities via jasper. Ensure your system's safety with the most recent updates accessible.
An update that fixes two vulnerabilities is now available.

Description

Specially crafted JPEG2000 files could cause a heap buffer

overflow in jasper (CVE-2011-4516, CVE-2011-4517)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch jasper-5543

- openSUSE 11.3:

zypper in -t patch jasper-5543

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

jasper-1.900.1-146.147.1

libjasper-devel-1.900.1-146.147.1

libjasper1-1.900.1-146.147.1

- openSUSE 11.4 (x86_64):

libjasper1-32bit-1.900.1-146.147.1

- openSUSE 11.3 (i586 x86_64):

jasper-1.900.1-141.3.1

libjasper-1.900.1-141.3.1

libjasper-devel-1.900.1-141.3.1

- openSUSE 11.3 (x86_64):

libjasper-32bit-1.900.1-141.3.1

References

https://www.suse.com/security/cve/CVE-2011-4516.html

https://www.suse.com/security/cve/CVE-2011-4517.html

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2011:1328-1
Rating: important
Affected Products: openSUSE 11.4 openSUSE 11.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here