SUSE-SU-2021:2159-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2159-1
SUSE-SU-2021:2159-1
Summary: Security update for openexr
Details: This update for openexr fixes the following issues: - Fixed CVE-2021-3479 [bsc#1184354]: Out-of-memory caused by allocation of a very large buffer - Fixed CVE-2021-3605 [bsc#1187395]: Heap buffer overflow in the rleUncompress function - Fixed CVE-2021-3598 [bsc#1187310]: Heap buffer overflow in Imf_3_1:CharPtrIO:readChars
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212159-1/, https://bugzilla.suse.com/1184354, https://bugzilla.suse.com/1187310, https://bugzilla.suse.com/1187395, https://www.suse.com/security/cve/CVE-2021-3479, https://www.suse.com/security/cve/CVE-2021-3598, https://www.suse.com/security/cve/CVE-2021-3605
Affected packages
Package
Name: openexr
Purl: pkg:rpm/suse/openexr&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
