Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE Linux 12: SUSE-SU-2017:0084-1 Critical: Jasper Buffer Overflow

suse
Calendar Grey January 8, 2017
Dist Suse Esm H88
A crucial notification for Jaspar tackles significant concerns in SUSE Linux. Apply the most recent updates to maintain system safety.
An update that fixes 5 vulnerabilities is now available

Summary

This update for jasper fixes the following issues: - CVE-2016-8654: Heap-based buffer overflow in QMFB code in JPC codec. (bsc#1012530) - CVE-2016-9395: Invalid jasper files could lead to abort of the library caused by attacker provided image. (bsc#1010977) - CVE-2016-9398: Invalid jasper files could lead to abort of the library caused by attacker provided image. (bsc#1010979) - CVE-2016-9560: Stack-based buffer overflow in jpc_tsfb_getbands2. (bsc#1011830) - CVE-2016-9591: Use-after-free on heap in jas_matrix_destroy. (bsc#1015993) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-27=1

References

#1010977 #1010979 #1011830 #1012530 #1015993

Cross- CVE-2016-8654 CVE-2016-9395 CVE-2016-9398

CVE-2016-9560 CVE-2016-9591

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Software Development Kit 12-SP1

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Desktop 12-SP2

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2016-8654.html

https://www.suse.com/security/cve/CVE-2016-9395.html

https://www.suse.com/security/cve/CVE-2016-9398.html

https://www.suse.com/security/cve/CVE-2016-9560.html

https://www.suse.com/security/cve/CVE-2016-9591.html

https://bugzilla.suse.com/1010977

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0084-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here