SUSE-SU-2018:0585-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0585-1
SUSE-SU-2018:0585-1
Summary: Security update for openexr
Details: This update for openexr fixes the following issues: * CVE-2017-9110: In OpenEXR, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash. (bsc#1040107) * CVE-2017-9114: In OpenEXR, an invalid read of size 1 in the refill function in ImfFastHuf.cpp could cause the application to crash. (bsc#1040114) * CVE-2017-12596: In OpenEXR, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it could have resulted in denial of service or possibly unspecified other impact. (bsc#1052522)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180585-1/, https://bugzilla.suse.com/1040107, https://bugzilla.suse.com/1040114, https://bugzilla.suse.com/1052522, https://www.suse.com/security/cve/CVE-2017-12596, https://www.suse.com/security/cve/CVE-2017-9110, https://www.suse.com/security/cve/CVE-2017-9114
Affected packages
Package
Name: openexr
Purl: pkg:rpm/suse/openexr&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
