Mageia 2020-0189: openexr security update
Summary
The updated packages fix security vulnerabilities:
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read in ImfOptimizedPixelReading.h. (CVE-2020-11758)
An issue was discovered in OpenEXR before 2.4.1. Because of integer
overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and
readSampleCountForLineBlock, an attacker can write to an out-of-bounds
pointer. (CVE-2020-11759)
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read during RLE uncompression in rleUncompress in ImfRle.cpp.
(CVE-2020-11760)
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read during Huffman uncompression, as demonstrated by FastHufDecoder::refill
in ImfFastHuf.cpp. (CVE-2020-11761)
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when
handling the UNKNOWN compression case. (CVE-2020-11762)
An issue was discovered in OpenEXR befo...
References
- https://bugs.mageia.org/show_bug.cgi?id=26551
- https://ubuntu.com/security/notices/USN-4339-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11758
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11759
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11760
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11761
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11762
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11763
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11764
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11765
Resolution
MGASA-2020-0189 - Updated openexr packages fix security vulnerabilities
SRPMS
- 7/core/openexr-2.3.0-2.2.mga7