SUSE-SU-2021:2793-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2793-1
SUSE-SU-2021:2793-1
Summary: Security update for openexr
Details: This update for openexr fixes the following issues: - CVE-2021-20298 [bsc#1188460]: Fixed Out-of-memory in B44Compressor - CVE-2021-20299 [bsc#1188459]: Fixed Null-dereference READ in Imf_2_5:Header:operator - CVE-2021-20300 [bsc#1188458]: Fixed Integer-overflow in Imf_2_5:hufUncompress - CVE-2021-20302 [bsc#1188462]: Fixed Floating-point-exception in Imf_2_5:precalculateTileInfot - CVE-2021-20303 [bsc#1188457]: Fixed Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer - CVE-2021-20304 [bsc#1188461]: Fixed Undefined-shift in Imf_2_5:hufDecode
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212793-1/, https://bugzilla.suse.com/1188457, https://bugzilla.suse.com/1188458, https://bugzilla.suse.com/1188459, https://bugzilla.suse.com/1188460, https://bugzilla.suse.com/1188461, https://bugzilla.suse.com/1188462, https://www.suse.com/security/cve/CVE-2021-20298, https://www.suse.com/security/cve/CVE-2021-20299, https://www.suse.com/security/cve/CVE-2021-20300, https://www.suse.com/security/cve/CVE-2021-20302, https://www.suse.com/security/cve/CVE-2021-20303, https://www.suse.com/security/cve/CVE-2021-20304, https://www.suse.com/security/cve/CVE-2021-3476
Affected packages
Package
Name: openexr
Purl: pkg:rpm/suse/openexr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
