VYPR

rpm package

suse/jasper&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP2

pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2

Vulnerabilities (17)

  • CVE-2021-3272Jan 27, 2021
    affected < 2.0.14-3.19.1fixed 2.0.14-3.19.1

    jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.

  • CVE-2020-27828Dec 11, 2020
    affected < 2.0.14-3.19.1fixed 2.0.14-3.19.1

    There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

  • CVE-2018-20622Dec 31, 2018
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.

  • CVE-2018-20570Dec 28, 2018
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

  • CVE-2018-19543Nov 26, 2018
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

  • CVE-2018-19139Nov 9, 2018
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.

  • CVE-2018-18873Oct 31, 2018
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.

  • CVE-2018-9154May 4, 2018
    affected < 2.0.14-3.11.8fixed 2.0.14-3.11.8

    There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745.

  • CVE-2018-9252Apr 4, 2018
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

  • CVE-2017-14132MedSep 4, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4,

  • CVE-2017-9782MedJun 21, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.

  • CVE-2016-9399HigMar 23, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

  • CVE-2016-9398HigMar 23, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

  • CVE-2017-5505MedMar 16, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    The jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.

  • CVE-2017-5504MedMar 1, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.

  • CVE-2017-5503MedMar 1, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    The dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via a crafted image.

  • CVE-2017-5499MedMar 1, 2017
    affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1

    Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.