openSUSE-SU-2021:0670-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0670-1
openSUSE-SU-2021:0670-1
Summary: Security update for openexr
Details: This update for openexr fixes the following issues: - CVE-2021-23215: Fixed an integer-overflow in Imf_2_5:DwaCompressor:initializeBuffers (bsc#1185216). - CVE-2021-26260: Fixed an Integer-overflow in Imf_2_5:DwaCompressor:initializeBuffers (bsc#1185217). - CVE-2021-20296: Fixed a Null Pointer dereference in Imf_2_5:hufUncompress (bsc#1184355). - CVE-2021-3477: Fixed a Heap-buffer-overflow in Imf_2_5::DeepTiledInputFile::readPixelSampleCounts (bsc#1184353). - CVE-2021-3479: Fixed an Out-of-memory caused by allocation of a very large buffer (bsc#1184354). This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/XRXYHURHLDTSCIDOVAICJNNLPZTJP6NQ/, https://bugzilla.suse.com/1184353, https://bugzilla.suse.com/1184354, https://bugzilla.suse.com/1184355, https://bugzilla.suse.com/1185216, https://bugzilla.suse.com/1185217, https://www.suse.com/security/cve/CVE-2021-20296, https://www.suse.com/security/cve/CVE-2021-23215, https://www.suse.com/security/cve/CVE-2021-26260, https://www.suse.com/security/cve/CVE-2021-3477, https://www.suse.com/security/cve/CVE-2021-3479
Affected packages
Package
Name: openexr
Purl: pkg:rpm/opensuse/openexr&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
