Описание
Security update for openexr
This update for openexr fixes the following issues:
- CVE-2017-14988: Fixed a denial of service in Header::readfrom() (bsc#1061305).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.0
libIlmImf-2_2-23-2.2.1-lp151.4.6.1
libIlmImf-2_2-23-32bit-2.2.1-lp151.4.6.1
libIlmImfUtil-2_2-23-2.2.1-lp151.4.6.1
libIlmImfUtil-2_2-23-32bit-2.2.1-lp151.4.6.1
openexr-2.2.1-lp151.4.6.1
openexr-devel-2.2.1-lp151.4.6.1
openexr-doc-2.2.1-lp151.4.6.1
openSUSE Leap 15.1
libIlmImf-2_2-23-2.2.1-lp151.4.6.1
libIlmImf-2_2-23-32bit-2.2.1-lp151.4.6.1
libIlmImfUtil-2_2-23-2.2.1-lp151.4.6.1
libIlmImfUtil-2_2-23-32bit-2.2.1-lp151.4.6.1
openexr-2.2.1-lp151.4.6.1
openexr-devel-2.2.1-lp151.4.6.1
openexr-doc-2.2.1-lp151.4.6.1
Ссылки
- E-Mail link for openSUSE-SU-2019:1954-1
- SUSE Security Ratings
- SUSE Bug 1061305
- SUSE CVE CVE-2017-14988 page
Описание
** DISPUTED ** Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputFile function in IlmImf/ImfCRgbaFile.cpp. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid.
Затронутые продукты
openSUSE Leap 15.0:libIlmImf-2_2-23-2.2.1-lp151.4.6.1
openSUSE Leap 15.0:libIlmImf-2_2-23-32bit-2.2.1-lp151.4.6.1
openSUSE Leap 15.0:libIlmImfUtil-2_2-23-2.2.1-lp151.4.6.1
openSUSE Leap 15.0:libIlmImfUtil-2_2-23-32bit-2.2.1-lp151.4.6.1
Ссылки
- CVE-2017-14988
- SUSE Bug 1061305