Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2020:2689-1 Moderate: Jasper Security Update Instructions

suse
Calendar Grey September 21, 2020
Dist Suse Esm H88
SUSE Security Patch for libpng addresses several vulnerabilities, enhancing overall security and reliability of the system against potential attacks.
An update that fixes 14 vulnerabilities is now available

Summary

This update for jasper fixes the following issues: - CVE-2016-9398: Improved patch for already fixed issue (bsc#1010979). - CVE-2016-9399: Fix assert in calcstepsizes (bsc#1010980). - CVE-2017-5499: Validate component depth bit (bsc#1020451). - CVE-2017-5503: Check bounds in jas_seq2d_bindsub() (bsc#1020456). - CVE-2017-5504: Check bounds in jas_seq2d_bindsub() (bsc#1020458). - CVE-2017-5505: Check bounds in jas_seq2d_bindsub() (bsc#1020460). - CVE-2017-14132: Fix heap base overflow in by checking components (bsc#1057152). - CVE-2018-9252: Fix reachable assertion in jpc_abstorelstepsize (bsc#1088278). - CVE-2018-18873: Fix null pointer deref in ras_putdatastd (bsc#1114498). - CVE-2018-19139: Fix mem leaks by registering jpc_unk_destroyparms (bsc#1115637).

References

#1010979 #1010980 #1020451 #1020456 #1020458

#1020460 #1045450 #1057152 #1088278 #1114498

#1115637 #1117328 #1120805 #1120807

Cross- CVE-2016-9398 CVE-2016-9399 CVE-2017-14132

CVE-2017-5499 CVE-2017-5503 CVE-2017-5504

CVE-2017-5505 CVE-2017-9782 CVE-2018-18873

CVE-2018-19139 CVE-2018-19543 CVE-2018-20570

CVE-2018-20622 CVE-2018-9252

Affected Products:

SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1

SUSE Linux Enterprise Module for Desktop Applications 15-SP2

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2016-9398.html

https://www.suse.com/security/cve/CVE-2016-9399.html

Announcement ID: SUSE-SU-2020:2689-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here