Hash: SHA512

Package        : openexr
Version        : 1.6.1-6+deb7u1
CVE ID         : CVE-2017-9110 CVE-2017-9112 CVE-2017-9116
Debian Bug     : 864078

Brandon Perry discovered that openexr, a high dynamic-range (HDR) image
library, was affected by an integer overflow vulnerability and missing
boundary checks that would allow a remote attacker to cause a denial of
service (application crash) via specially crafted image files.

For Debian 7 "Wheezy", these problems have been fixed in version
1.6.1-6+deb7u1.

We recommend that you upgrade your openexr packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1083-1: openexr security update

September 1, 2017
Brandon Perry discovered that openexr, a high dynamic-range (HDR) image library, was affected by an integer overflow vulnerability and missing boundary checks that would allow a re...

Summary

For Debian 7 "Wheezy", these problems have been fixed in version
1.6.1-6+deb7u1.

We recommend that you upgrade your openexr packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : openexr
Version : 1.6.1-6+deb7u1
CVE ID : CVE-2017-9110 CVE-2017-9112 CVE-2017-9116
Debian Bug : 864078

Related News