Описание
Security update for openexr
This update for openexr fixes the following issues:
Security issue fixed:
- CVE-2017-9111: Fixed an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h (bsc#1040109).
- CVE-2017-9113: Fixed an invalid write of size 1 in the bufferedReadPixels function in ImfInputFile.cpp (bsc#1040113).
- CVE-2017-9115: Fixed an invalid write of size 2 in the = operator function inhalf.h (bsc#1040115).
- CVE-2018-18444: Fixed Out-of-bounds write in makeMultiView.cpp (bsc#1113455).
- CVE-2017-9112: Fixed invalid read of size 1 in the getBits function in ImfHuf.cpp (bsc#1040112).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP4
SUSE Linux Enterprise Workstation Extension 12 SP4
Ссылки
- Link for SUSE-SU-2019:1962-1
- E-Mail link for SUSE-SU-2019:1962-1
- SUSE Security Ratings
- SUSE Bug 1040109
- SUSE Bug 1040112
- SUSE Bug 1040113
- SUSE Bug 1040115
- SUSE Bug 1113455
- SUSE CVE CVE-2017-9111 page
- SUSE CVE CVE-2017-9112 page
- SUSE CVE CVE-2017-9113 page
- SUSE CVE CVE-2017-9115 page
- SUSE CVE CVE-2018-18444 page
Описание
In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code.
Затронутые продукты
Ссылки
- CVE-2017-9111
- SUSE Bug 1040109
Описание
In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cpp could cause the application to crash.
Затронутые продукты
Ссылки
- CVE-2017-9112
- SUSE Bug 1040112
Описание
In OpenEXR 2.2.0, an invalid write of size 1 in the bufferedReadPixels function in ImfInputFile.cpp could cause the application to crash or execute arbitrary code.
Затронутые продукты
Ссылки
- CVE-2017-9113
- SUSE Bug 1040113
Описание
In OpenEXR 2.2.0, an invalid write of size 2 in the = operator function in half.h could cause the application to crash or execute arbitrary code.
Затронутые продукты
Ссылки
- CVE-2017-9115
- SUSE Bug 1040115
Описание
makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified other impact.
Затронутые продукты
Ссылки
- CVE-2018-18444
- SUSE Bug 1113455