openSUSE-SU-2021:2793-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:2793-1
openSUSE-SU-2021:2793-1
Summary: Security update for openexr
Details: This update for openexr fixes the following issues: - CVE-2021-20298 [bsc#1188460]: Fixed Out-of-memory in B44Compressor - CVE-2021-20299 [bsc#1188459]: Fixed Null-dereference READ in Imf_2_5:Header:operator - CVE-2021-20300 [bsc#1188458]: Fixed Integer-overflow in Imf_2_5:hufUncompress - CVE-2021-20302 [bsc#1188462]: Fixed Floating-point-exception in Imf_2_5:precalculateTileInfot - CVE-2021-20303 [bsc#1188457]: Fixed Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer - CVE-2021-20304 [bsc#1188461]: Fixed Undefined-shift in Imf_2_5:hufDecode
References: https://lists.opensuse.org/archives/list/[email protected]/thread/I6OVSOAQ3PQXBTM46SMNT6H3XP45CC7L/, https://bugzilla.suse.com/1188457, https://bugzilla.suse.com/1188458, https://bugzilla.suse.com/1188459, https://bugzilla.suse.com/1188460, https://bugzilla.suse.com/1188461, https://bugzilla.suse.com/1188462, https://www.suse.com/security/cve/CVE-2021-20298, https://www.suse.com/security/cve/CVE-2021-20299, https://www.suse.com/security/cve/CVE-2021-20300, https://www.suse.com/security/cve/CVE-2021-20302, https://www.suse.com/security/cve/CVE-2021-20303, https://www.suse.com/security/cve/CVE-2021-20304, https://www.suse.com/security/cve/CVE-2021-3476
Affected packages
Package
Name: openexr
Purl: pkg:rpm/opensuse/openexr&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
