Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (1h)  pkgsrc-2024Q1 (6d)  pkgsrc-2023Q4 (53d)  pkgsrc-2023Q2 (85d)  pkgsrc-2023Q3 (165d) 

2024-05-23 23:45:49 UTC Now

2015-01-15 09:37:05 UTC MAIN commitmail json YAML

  openSUSE Security Update: Security update for jasper
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2015:0042-1
Rating:            moderate
References:        #909474 #909475
Cross-References:  CVE-2014-8137
Affected Products:
                    openSUSE 13.1
______________________________________________________________________________

  An update that solves one vulnerability and has one errata
  is now available.

Description:

        The follow issues were fixed with this update:
        - CVE-2014-8137  double-free in jas_iccattrval_destroy()(bnc#909474)
        - CVE-2014-8138  heap overflow in jas_decode() (bnc#909475)

References:

  http://support.novell.com/security/cve/CVE-2014-8137.html
  https://bugzilla.suse.com/show_bug.cgi?id=909474
  https://bugzilla.suse.com/show_bug.cgi?id=909475

(obache)