Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 10: FEDORA-2009-8136 Critical OpenEXR Integer Overflow

fedora
Calendar Grey July 31, 2009
Dist Fedora Esm H88
Fedora 10 enhancements feature patches for GIMP focusing on memory safety problems related to buffer overflows and null pointer dereferences.

Summary

OpenEXR is a high dynamic-range (HDR) image file format developed by Industrial

Light & Magic for use in computer imaging applications. This package contains

libraries and sample applications for handling the format.

ChangeLog:

* Wed Jul 29 2009 Rex Dieter 1.6.1-8

- CVE-2009-1720 OpenEXR: Multiple integer overflows (#513995)

- CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression (#514003)

* Fri Jul 24 2009 Fedora Release Engineering - 1.6.1-7

- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

* Mon Feb 23 2009 Fedora Release Engineering - 1.6.1-6

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

* Fri Dec 12 2008 Caolán McNamara 1.6.1-5

- rebuild to get provides pkgconfig(OpenEXR)

References:

[ 1 ] Bug #513995 - CVE-2009-1720 OpenEXR: Multiple integer overflows

https://bugzilla.redhat.com/show_bug.cgi?id=513995

[ 2 ] Bug #514003 - CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression

https://bugzilla.redhat.com/show_bug.cgi?id=514003

This update can be installed with the "yum" update program. Use

su -c 'yum update OpenEXR' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: OpenEXR
Product: Fedora 10
Version: 1.6.1
Release: 8.fc10
Summary: A high dynamic-range (HDR) image file format

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here