File _patchinfo of Package patchinfo.4397

<patchinfo incident="4397">
  <issue id="1020353" tracker="bnc">VUL-1: CVE-2017-5498: jasper: left-shift undefined behaviour</issue>
  <issue id="1029497" tracker="bnc">VUL-0: CVE-2016-10251: jasper: use of uninitialized value in jpc_pi_nextcprl (jpc_t2cod.c)</issue>
  <issue id="1018088" tracker="bnc">VUL-1: CVE-2016-9600: jasper: Null Pointer Dereference due to missing check for UNKNOWN color space in JP2 encoder</issue>
  <issue id="1021868" tracker="bnc">VUL-1: CVE-2017-6850: jasper: NULL pointer dereference in jp2_cdef_destroy (jp2_cod.c)</issue>
  <issue id="1015400" tracker="bnc">VUL-0: CVE-2016-9583: jasper: Out of bounds heap read in jpc_pi_nextpcrl()</issue>
  <issue id="2016-9600" tracker="cve" />
  <issue id="2017-5498" tracker="cve" />
  <issue id="2016-10251" tracker="cve" />
  <issue id="2017-6850" tracker="cve" />
  <issue id="2016-9583" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>fstrba</packager>
  <description>
This update for jasper fixes the following issues:

Security issues fixed:
- CVE-2016-9600: Null Pointer Dereference due to missing check for UNKNOWN color space in JP2 encoder (bsc#1018088)
- CVE-2016-10251: Use of uninitialized value in jpc_pi_nextcprl (jpc_t2cod.c) (bsc#1029497)
- CVE-2017-5498: left-shift undefined behaviour (bsc#1020353)
- CVE-2017-6850: NULL pointer dereference in jp2_cdef_destroy (jp2_cod.c) (bsc#1021868)
- CVE-2016-9583: Out of bounds heap read in jpc_pi_nextpcrl() (bsc#1015400)
</description>
  <summary>Security update for jasper</summary>
</patchinfo>
openSUSE Build Service is sponsored by