MGASA-2018-0032

Source
https://advisories.mageia.org/MGASA-2018-0032.html
Import Source
https://advisories.mageia.org/MGASA-2018-0032.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0032
Related
Published
2018-01-03T14:22:14Z
Modified
2018-01-03T13:50:24Z
Summary
Updated OpenEXR packages fix security vulnerability
Details

In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash (CVE-2017-9110).

In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cpp could cause the application to crash (CVE-2017-9112).

In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip.cpp could cause the application to crash (CVE-2017-9116).

References
Credits

Affected packages

Mageia:5 / OpenEXR

Package

Name
OpenEXR
Purl
pkg:rpm/mageia/OpenEXR?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.0-4.1.mga5

Ecosystem specific

{
    "section": "core"
}