rpm package
suse/jasper&distro=SUSE Linux Enterprise Module for Package Hub 15 SP1
pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1
Vulnerabilities (15)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-20622 | — | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Dec 31, 2018 | JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. | ||
| CVE-2018-20570 | — | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Dec 28, 2018 | jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read. | ||
| CVE-2018-19543 | — | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. | ||
| CVE-2018-19139 | — | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Nov 9, 2018 | An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c. | ||
| CVE-2018-18873 | — | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Oct 31, 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c. | ||
| CVE-2018-9154 | — | < 2.0.14-3.11.8 | 2.0.14-3.11.8 | May 4, 2018 | There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745. | ||
| CVE-2018-9252 | — | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Apr 4, 2018 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c. | ||
| CVE-2017-14132 | Med | 6.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Sep 4, 2017 | JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, | |
| CVE-2017-9782 | Med | 5.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Jun 21, 2017 | JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c. | |
| CVE-2016-9399 | Hig | 7.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Mar 23, 2017 | The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors. | |
| CVE-2016-9398 | Hig | 7.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Mar 23, 2017 | The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors. | |
| CVE-2017-5505 | Med | 5.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Mar 16, 2017 | The jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image. | |
| CVE-2017-5504 | Med | 5.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Mar 1, 2017 | The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image. | |
| CVE-2017-5503 | Med | 5.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Mar 1, 2017 | The dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via a crafted image. | |
| CVE-2017-5499 | Med | 5.5 | < 2.0.14-3.16.1 | 2.0.14-3.16.1 | Mar 1, 2017 | Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file. |
- CVE-2018-20622Dec 31, 2018affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
- CVE-2018-20570Dec 28, 2018affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
- CVE-2018-19543Nov 26, 2018affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
- CVE-2018-19139Nov 9, 2018affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
- CVE-2018-18873Oct 31, 2018affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
- CVE-2018-9154May 4, 2018affected < 2.0.14-3.11.8fixed 2.0.14-3.11.8
There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745.
- CVE-2018-9252Apr 4, 2018affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4,
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
The jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
The dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via a crafted image.
- affected < 2.0.14-3.16.1fixed 2.0.14-3.16.1
Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.