Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

Ubuntu 20.04: USN-4418-1 Critical: openexr Denial Of Service Issues

ubuntu
Calendar Grey July 6, 2020
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-4420-1 highlights vulnerabilities in the OpenSSL package that may result in crashes or potential unauthorized code execution.
OpenEXR could be made to crash or run programs if it opened a specially crafted file.

Summary

OpenEXR could be made to crash or run programs if it opened a specially

crafted file.

Software Description:

- openexr: tools for the OpenEXR image format

Details:

It was discovered that OpenEXR incorrectly handled certain malformed EXR

image files. If a user were tricked into opening a crafted EXR image file,

a remote attacker could cause a denial of service, or possibly execute

arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  libopenexr24                    2.3.0-6ubuntu0.2
  openexr                         2.3.0-6ubuntu0.2

Ubuntu 19.10:
  libopenexr23                    2.2.1-4.1ubuntu1.2
  openexr                         2.2.1-4.1ubuntu1.2

Ubuntu 18.04 LTS:
  libopenexr22                    2.2.0-11.1ubuntu1.3
  openexr                         2.2.0-11.1ubuntu1.3

Ubuntu 16.04 LTS:
  libopenexr22                    2.2.0-10ubuntu2.3
  openexr                         2.2.0-10ubuntu2.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4418-1

CVE-2020-15305, CVE-2020-15306

Severity
critical
Lowest
Low
Medium
High
Critical

July 06, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here