{"affected":[{"ecosystem_specific":{"binaries":[{"libjasper1":"1.900.14-195.15.1","libjasper1-32bit":"1.900.14-195.15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP4","name":"jasper","purl":"pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.900.14-195.15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjasper-devel":"1.900.14-195.15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP4","name":"jasper","purl":"pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.900.14-195.15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjasper1":"1.900.14-195.15.1","libjasper1-32bit":"1.900.14-195.15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4","name":"jasper","purl":"pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.900.14-195.15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjasper1":"1.900.14-195.15.1","libjasper1-32bit":"1.900.14-195.15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","name":"jasper","purl":"pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.900.14-195.15.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for jasper fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2018-19540: Fixed  a heap based overflow in jas_icctxtdesc_input (bsc#1117508).\n- CVE-2018-19541: Fix heap based overread in jas_image_depalettize (bsc#1117507).\n- CVE-2018-19542: Fixed a denial of service in jp2_decode (bsc#1117505).\n- CVE-2018-19539: Fixed a denial of service in jas_image_readcmpt (bsc#1117511).\n- CVE-2016-9396: Fixed a denial of service in jpc_cox_getcompparms (bsc#1010783).\n","id":"SUSE-SU-2019:2513-1","modified":"2019-10-02T08:48:34Z","published":"2019-10-02T08:48:34Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20192513-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1010783"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117508"},{"type":"REPORT","url":"https://bugzilla.suse.com/1117511"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9396"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19540"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19542"}],"related":["CVE-2016-9396","CVE-2018-19539","CVE-2018-19540","CVE-2018-19541","CVE-2018-19542"],"summary":"Security update for jasper","upstream":["CVE-2016-9396","CVE-2018-19539","CVE-2018-19540","CVE-2018-19541","CVE-2018-19542"]}