An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for jpeg ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:14069-1 Rating: low References: #1122299 #1128712 Cross-References: CVE-2018-11212 CVE-2018-14498 Affected Products: SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for jpeg fixes the following issue: Security issue fixed: - CVE-2018-14498: Fixed a heap-based buffer over read in get_8bit_row function which could allow to an attacker to cause denial of service (bsc#1128712). - CVE-2018-11212: Fixed divide by zero in alloc_sarray function in jmemmgr.c (bsc#1122299). - CVE-2018-14498: Fixed denial of service in get_8bit_row in rdbmp.c (bsc#1128712). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-jpeg-14069=1 Package List: - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): jpeg-debuginfo-6b-879.12.12.1 jpeg-debugsource-6b-879.12.12.1 References: https://www.suse.com/security/cve/CVE-2018-11212.html https://www.suse.com/security/cve/CVE-2018-14498.html https://bugzilla.suse.com/1122299 https://bugzilla.suse.com/1128712 _______________________________________________ sle-security-updates mailing list
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for jpeg ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1825-1 Rating: moderate References: #1062937 #1096209 #1098155 Cross-References: CVE-2017-15232 CVE-2018-1152 CVE-2018-11813 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for jpeg fixes the following issues: * CVE-2017-15232: NULL pointer dereferences in jdpostct.c and jquant1.c could lead to denial of service (crash) when processing images [bsc#1062937] * CVE-2018-11813: Fixed the end-of-file mishandling in read_pixel in rdtarga.c, which allowed remote attackers to cause a denial-of-service via crafted JPG files due to a large loop [bsc#1096209] * CVE-2018-1152: Fixed a denial of service in start_input_bmp() rdbmp.c caused by a divide by zero when processing a crafted BMP image [bsc#1098155] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-jpeg-13681=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-jpeg-13681=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-jpeg-13681=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libjpeg-devel-6.2.0-879.12.7.1 - SUSE Linux Enterprise SoftwareDevelopment Kit 11-SP4 (ppc64 s390x x86_64): libjpeg-devel-32bit-6.2.0-879.12.7.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): jpeg-6b-879.12.7.1 libjpeg-6.2.0-879.12.7.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libjpeg-32bit-6.2.0-879.12.7.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libjpeg-x86-6.2.0-879.12.7.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): jpeg-debuginfo-6b-879.12.7.1 jpeg-debugsource-6b-879.12.7.1 References: https://www.suse.com/security/cve/CVE-2017-15232.html https://www.suse.com/security/cve/CVE-2018-1152.html https://www.suse.com/security/cve/CVE-2018-11813.html https://bugzilla.suse.com/1062937 https://bugzilla.suse.com/1096209 https://bugzilla.suse.com/1098155 . SUSE addresses multiple vulnerabilities in png that may trigger denial of service. Users of SUSE Linux are advised to apply the update.. SUSE Linux, jpeg update, moderate security advisory, denial of service. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.