OpenEXR could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-5150-1 November 17, 2021 openexr vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: OpenEXR could be made to crash if it opened a specially crafted file. Software Description: - openexr: tools for the OpenEXR image format Details: It was discovered that OpenEXR incorrectly handled certain EXR image files. An attacker could possibly use this issue to cause a crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libopenexr22 2.2.0-11.1ubuntu1.9 openexr 2.2.0-11.1ubuntu1.9 Ubuntu 16.04 ESM: libopenexr22 2.2.0-10ubuntu2.6+esm3 openexr 2.2.0-10ubuntu2.6+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5150-1 CVE-2021-3941 Package Information: https://launchpad.net/ubuntu/+source/openexr/2.2.0-11.1ubuntu1.9 . Ubuntu 18.04 and 16.04 users are experiencing stability issues with OpenEXR library versions that can lead to crashes. Check for updates or patches to address these vulnerabilities. OpenEXR Security Patch, Ubuntu OpenEXR Update, EXR File Crash Issue. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.