MGASA-2019-0166 - Updated openexr packages fix security vulnerabilities

Publication date: 12 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0166.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-18444

Updated openexr package fixes security vulnerabilities:

It was discovered that makeMultiView.cpp in exrmultiview in OpenEXR
2.3.0 has an out-of-bounds write, leading to an assertion failure or
possibly unspecified other impact (CVE-2018-18444).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24759
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18444

SRPMS:
- 6/core/openexr-2.2.0-10.1.mga6

Mageia 2019-0166: openexr security update

Updated openexr package fixes security vulnerabilities: It was discovered that makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an asserti...

Summary

Updated openexr package fixes security vulnerabilities:
It was discovered that makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified other impact (CVE-2018-18444).

References

- https://bugs.mageia.org/show_bug.cgi?id=24759

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18444

Resolution

MGASA-2019-0166 - Updated openexr packages fix security vulnerabilities

SRPMS

- 6/core/openexr-2.2.0-10.1.mga6

Severity
Publication date: 12 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0166.html
Type: security
CVE: CVE-2018-18444

Related News