File _patchinfo of Package patchinfo.4397
<patchinfo incident="4397">
<issue id="1020353" tracker="bnc">VUL-1: CVE-2017-5498: jasper: left-shift undefined behaviour</issue>
<issue id="1029497" tracker="bnc">VUL-0: CVE-2016-10251: jasper: use of uninitialized value in jpc_pi_nextcprl (jpc_t2cod.c)</issue>
<issue id="1018088" tracker="bnc">VUL-1: CVE-2016-9600: jasper: Null Pointer Dereference due to missing check for UNKNOWN color space in JP2 encoder</issue>
<issue id="1021868" tracker="bnc">VUL-1: CVE-2017-6850: jasper: NULL pointer dereference in jp2_cdef_destroy (jp2_cod.c)</issue>
<issue id="1015400" tracker="bnc">VUL-0: CVE-2016-9583: jasper: Out of bounds heap read in jpc_pi_nextpcrl()</issue>
<issue id="2016-9600" tracker="cve" />
<issue id="2017-5498" tracker="cve" />
<issue id="2016-10251" tracker="cve" />
<issue id="2017-6850" tracker="cve" />
<issue id="2016-9583" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>fstrba</packager>
<description>
This update for jasper fixes the following issues:
Security issues fixed:
- CVE-2016-9600: Null Pointer Dereference due to missing check for UNKNOWN color space in JP2 encoder (bsc#1018088)
- CVE-2016-10251: Use of uninitialized value in jpc_pi_nextcprl (jpc_t2cod.c) (bsc#1029497)
- CVE-2017-5498: left-shift undefined behaviour (bsc#1020353)
- CVE-2017-6850: NULL pointer dereference in jp2_cdef_destroy (jp2_cod.c) (bsc#1021868)
- CVE-2016-9583: Out of bounds heap read in jpc_pi_nextpcrl() (bsc#1015400)
</description>
<summary>Security update for jasper</summary>
</patchinfo>