Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE: 2017:2567-1 Critical: OpenJPEG2 Buffer Overflow Update

opensuse
Calendar Grey September 26, 2017
Dist Opensuse Esm H88
New patch released for openjpeg2 on openSUSE, addressing several urgent vulnerabilities while implementing essential security enhancements.
An update that fixes 15 vulnerabilities is now available

Description

This update for openjpeg2 fixes the following issues:

* CVE-2016-9114: NULL Pointer Access in function imagetopnm of

convert.c:1943(jp2) could lead to crash [bsc#1007740]

* CVE-2016-9115: Heap Buffer Overflow in function imagetotga of

convert.c(jp2) [bsc#1007741]

* CVE-2016-9580, CVE-2016-9581: Possible Heap buffer overflow via integer

overflow and infite loop [bsc#1014975]

* CVE-2016-9117: NULL Pointer Access in function imagetopnm of

convert.c(jp2):1289 [bsc#1007743]

* CVE-2016-9118: Heap Buffer Overflow in function pnmtoimage of convert.c

[bsc#1007744]

* CVE-2016-9112: FPE(Floating Point Exception) in lib/openjp2/pi.c:523

[bsc#1007747]

* CVE-2016-9116: NULL Pointer Access in function imagetopnm of

convert.c:2226(jp2) [bsc#1007742]

* CVE-2016-9113: NULL point dereference in function imagetobmp of

convertbmp.c could lead to crash [bsc#1007739]

* CVE-2016-9572 CVE-2016-9573: Insuficient check in imagetopnm() could

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2017-1090=1

To bring your system up-to-date, use "zypper patch".

Package List

- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64):

libopenjp2-7-2.1.0-5.1

libopenjp2-7-2.1.0-6.1

openjpeg2-2.1.0-5.1

openjpeg2-2.1.0-6.1

openjpeg2-devel-2.1.0-5.1

openjpeg2-devel-2.1.0-6.1

References

https://www.suse.com/security/cve/CVE-2015-8871.html

https://www.suse.com/security/cve/CVE-2016-7163.html

https://www.suse.com/security/cve/CVE-2016-7445.html

https://www.suse.com/security/cve/CVE-2016-8332.html

https://www.suse.com/security/cve/CVE-2016-9112.html

https://www.suse.com/security/cve/CVE-2016-9113.html

https://www.suse.com/security/cve/CVE-2016-9114.html

https://www.suse.com/security/cve/CVE-2016-9115.html

https://www.suse.com/security/cve/CVE-2016-9116.html

https://www.suse.com/security/cve/CVE-2016-9117.html

https://www.suse.com/security/cve/CVE-2016-9118.html

https://www.suse.com/security/cve/CVE-2016-9572.html

https://www.suse.com/security/cve/CVE-2016-9573.html

https://www.suse.com/security/cve/CVE-2016-9580.html

https://www.suse.com/security/cve/CVE-2016-9581.html

https://bugzilla.suse.com/1002414

https://bugzilla.suse.com/1007739

https://bugzilla.suse.com/1007740

https://bugzilla.suse.com/1007741

https://bugzilla.suse.com/1007742

https://bugzilla.suse.com/1007743

https://bugzilla.suse....

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:2567-1
Rating: important
Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here