Bug 1202642 - (CVE-2022-2963) VUL-0: CVE-2022-2963: jasper: jasper: memory leaks in function cmdopts_parse
(CVE-2022-2963)
VUL-0: CVE-2022-2963: jasper: jasper: memory leaks in function cmdopts_parse
Status: IN_PROGRESS
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/340536/
CVSSv3.1:SUSE:CVE-2022-2963:6.2:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-08-23 15:03 UTC by Gianluca Gabrielli
Modified: 2022-10-20 13:22 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Gianluca Gabrielli 2022-08-23 15:04:33 UTC
Affected packages:
 - SUSE:SLE-11:Update/jasper       1.900.14
 - SUSE:SLE-12:Update/jasper       1.900.14
 - SUSE:SLE-15:Update/jasper       2.0.14
 - openSUSE:Factory/jasper 3.0.6

Upstream patch [0].

[0] https://github.com/jasper-software/jasper/commit/d99636fad60629785efd1ef72da772a8ef68f54c
Comment 2 Thomas Leroy 2022-09-16 07:42:00 UTC
(In reply to Gianluca Gabrielli from comment #1)
> Affected packages:
>  - SUSE:SLE-11:Update/jasper       1.900.14
>  - SUSE:SLE-12:Update/jasper       1.900.14
>  - SUSE:SLE-15:Update/jasper       2.0.14
>  - openSUSE:Factory/jasper 3.0.6
> 
> Upstream patch [0].
> 
> [0]
> https://github.com/jasper-software/jasper/commit/
> d99636fad60629785efd1ef72da772a8ef68f54c
Any news on this Fridrich? :)
Comment 3 Michael Vetter 2022-09-16 09:36:41 UTC
(In reply to Thomas Leroy from comment #2)
> (In reply to Gianluca Gabrielli from comment #1)
> > Affected packages:
> >  - SUSE:SLE-11:Update/jasper       1.900.14
> >  - SUSE:SLE-12:Update/jasper       1.900.14
> >  - SUSE:SLE-15:Update/jasper       2.0.14
> >  - openSUSE:Factory/jasper 3.0.6
> > 
> > Upstream patch [0].
> > 
> > [0]
> > https://github.com/jasper-software/jasper/commit/
> > d99636fad60629785efd1ef72da772a8ef68f54c
> Any news on this Fridrich? :)

Seems I missed this bug when taking them over from Fridrich. I'll take a look.
Comment 7 Michael Vetter 2022-09-16 11:52:44 UTC
Factory: SR#1004089
SLE11: SR#280115
SLE12: SR#280116
SLE15: SR#280118
Comment 8 OBSbugzilla Bot 2022-09-16 12:15:03 UTC
This is an autogenerated message for OBS integration:
This bug (1202642) was mentioned in
https://build.opensuse.org/request/show/1004089 Factory / jasper
Comment 10 Swamp Workflow Management 2022-10-20 13:20:19 UTC
SUSE-SU-2022:3673-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1202642
CVE References: CVE-2022-2963
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    jasper-2.0.14-150000.3.28.1
openSUSE Leap 15.3 (src):    jasper-2.0.14-150000.3.28.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src):    jasper-2.0.14-150000.3.28.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src):    jasper-2.0.14-150000.3.28.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    jasper-2.0.14-150000.3.28.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    jasper-2.0.14-150000.3.28.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2022-10-20 13:22:34 UTC
SUSE-SU-2022:3672-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1202642
CVE References: CVE-2022-2963
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    jasper-1.900.14-195.34.1
SUSE Linux Enterprise Server 12-SP5 (src):    jasper-1.900.14-195.34.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.