Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE Linux Enterprise 12-SP2: 2016:3270-1 Critical: Openjpeg2 Buffer Crash

suse
Calendar Grey December 27, 2016
Dist Suse Esm H88
Critical news regarding openjpeg2 addresses 13 vulnerabilities in SUSE platforms, encompassing buffer overflow flaws and null pointer dereference problems.
An update that fixes 13 vulnerabilities is now available

Summary

This update for openjpeg2 fixes the following issues: * CVE-2016-9114: NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) could lead to crash [bsc#1007740] * CVE-2016-9115: Heap Buffer Overflow in function imagetotga of convert.c(jp2) [bsc#1007741] * CVE-2016-9580, CVE-2016-9581: Possible Heap buffer overflow via integer overflow and infite loop [bsc#1014975] * CVE-2016-9117: NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 [bsc#1007743] * CVE-2016-9118: Heap Buffer Overflow in function pnmtoimage of convert.c [bsc#1007744] * CVE-2016-9112: FPE(Floating Point Exception) in lib/openjp2/pi.c:523 [bsc#1007747] * CVE-2016-9116: NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) [bsc#1007742]

References

#1002414 #1007739 #1007740 #1007741 #1007742

#1007743 #1007744 #1007747 #1014543 #1014975

#999817

Cross- CVE-2016-7445 CVE-2016-8332 CVE-2016-9112

CVE-2016-9113 CVE-2016-9114 CVE-2016-9115

CVE-2016-9116 CVE-2016-9117 CVE-2016-9118

CVE-2016-9572 CVE-2016-9573 CVE-2016-9580

CVE-2016-9581

Affected Products:

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP2

https://www.suse.com/security/cve/CVE-2016-7445.html

https://www.suse.com/security/cve/CVE-2016-8332.html

https://www.suse.com/security/cve/CVE-2016-9112.html

https://www.suse.com/security/cve/CVE-2016-9113.html

https://www.suse.com/security/cve/CVE-2016-9114.html

https://www.suse.com/security/cve/CVE-2016-9115.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:3270-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here