Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 11: 2009-8132 Critical: OpenEXR Integer Overflow Threat

fedora
Calendar Grey July 31, 2009
Dist Fedora Esm H88
Essential patch for OpenEXR on Fedora 11 resolves various buffer overflow and incorrect pointer problems. Update immediately!

Summary

OpenEXR is a high dynamic-range (HDR) image file format developed by Industrial

Light & Magic for use in computer imaging applications. This package contains

libraries and sample applications for handling the format.

ChangeLog:

* Wed Jul 29 2009 Rex Dieter 1.6.1-8

- CVE-2009-1720 OpenEXR: Multiple integer overflows (#513995)

- CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression (#514003)

* Fri Jul 24 2009 Fedora Release Engineering - 1.6.1-7

- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

References:

[ 1 ] Bug #513995 - CVE-2009-1720 OpenEXR: Multiple integer overflows

https://bugzilla.redhat.com/show_bug.cgi?id=513995

[ 2 ] Bug #514003 - CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression

https://bugzilla.redhat.com/show_bug.cgi?id=514003

This update can be installed with the "yum" update program. Use

su -c 'yum update OpenEXR' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: OpenEXR
Product: Fedora 11
Version: 1.6.1
Release: 8.fc11
Summary: A high dynamic-range (HDR) image file format

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here