SUSE-SU-2021:1489-1
Dashboard / Vulnerabilities / SUSE-SU-2021:1489-1
SUSE-SU-2021:1489-1
Summary: Security update for openexr
Details: This update for openexr fixes the following issues: - CVE-2021-23215: Fixed an integer-overflow in Imf_2_5:DwaCompressor:initializeBuffers (bsc#1185216). - CVE-2021-26260: Fixed an Integer-overflow in Imf_2_5:DwaCompressor:initializeBuffers (bsc#1185217). - CVE-2021-20296: Fixed a Null Pointer dereference in Imf_2_5:hufUncompress (bsc#1184355). - CVE-2021-3477: Fixed a Heap-buffer-overflow in Imf_2_5::DeepTiledInputFile::readPixelSampleCounts (bsc#1184353). - CVE-2021-3479: Fixed an Out-of-memory caused by allocation of a very large buffer (bsc#1184354).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20211489-1/, https://bugzilla.suse.com/1184353, https://bugzilla.suse.com/1184354, https://bugzilla.suse.com/1184355, https://bugzilla.suse.com/1185216, https://bugzilla.suse.com/1185217, https://www.suse.com/security/cve/CVE-2021-20296, https://www.suse.com/security/cve/CVE-2021-23215, https://www.suse.com/security/cve/CVE-2021-26260, https://www.suse.com/security/cve/CVE-2021-3477, https://www.suse.com/security/cve/CVE-2021-3479
Affected packages
Package
Name: openexr
Purl: pkg:rpm/suse/openexr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
