This update for jasper fixes the following issues: - CVE-2016-8654: Heap-based buffer overflow in QMFB code in JPC codec. (bsc#1012530) - CVE-2016-9395: Invalid jasper files could lead to abort of the library caused by attacker provided image. (bsc#1010977) - CVE-2016-9398: Invalid jasper files could lead to abort of the library caused by attacker provided image. (bsc#1010979) - CVE-2016-9560: Stack-based buffer overflow in jpc_tsfb_getbands2. (bsc#1011830) - CVE-2016-9591: Use-after-free on heap in jas_matrix_destroy. (bsc#1015993) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-27=1
#1010977 #1010979 #1011830 #1012530 #1015993
Cross- CVE-2016-8654 CVE-2016-9395 CVE-2016-9398
CVE-2016-9560 CVE-2016-9591
Affected Products:
SUSE Linux Enterprise Software Development Kit 12-SP2
SUSE Linux Enterprise Software Development Kit 12-SP1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
SUSE Linux Enterprise Server 12-SP2
SUSE Linux Enterprise Server 12-SP1
SUSE Linux Enterprise Desktop 12-SP2
SUSE Linux Enterprise Desktop 12-SP1
https://www.suse.com/security/cve/CVE-2016-8654.html
https://www.suse.com/security/cve/CVE-2016-9395.html
https://www.suse.com/security/cve/CVE-2016-9398.html
https://www.suse.com/security/cve/CVE-2016-9560.html
https://www.suse.com/security/cve/CVE-2016-9591.html
https://bugzilla.suse.com/1010977
Get the latest Linux and open source security news straight to your inbox.