Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-26260: [SECURITY] Fedora 33 Update: mingw-OpenEXR-2.4.1-4.fc33 - package-announce

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVE
#windows#buffer_overflow

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2021-6af32bfcd2 2021-05-10 01:07:48.522423 -------------------------------------------------------------------------------- Name : mingw-OpenEXR Product : Fedora 33 Version : 2.4.1 Release : 4.fc33 URL : http://www.openexr.com/ Summary : MinGW Windows OpenEXR library Description : MinGW Windows OpenEXR library. -------------------------------------------------------------------------------- Update Information: Backport patches for CVE-2021-23169, CVE-2021-26260, CVE-2021-23215 -------------------------------------------------------------------------------- ChangeLog: * Sat May 1 2021 Sandro Mani <manisandro(a)gmail.com> - 2.4.1-4 - Backport patches for CVE-2021-23169, CVE-2021-26260, CVE-2021-23215 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1952357 - CVE-2021-26260 mingw-OpenEXR: OpenEXR: Integer-overflow in Imf_2_5::DwaCompressor::initializeBuffers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1952357 [ 2 ] Bug #1952444 - CVE-2021-23215 mingw-OpenEXR: OpenEXR: Integer-overflow in Imf_2_5::DwaCompressor::initializeBuffers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1952444 [ 3 ] Bug #1952477 - CVE-2021-23169 mingw-OpenEXR: OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1952477 -------------------------------------------------------------------------------- This update can be installed with the “dnf” update program. Use su -c ‘dnf upgrade --advisory FEDORA-2021-6af32bfcd2’ at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------

Related news

Debian Security Advisory 5299-1

Debian Linux Security Advisory 5299-1 - Multiple security vulnerabilities have been found in OpenEXR, command-line tools and a library for the OpenEXR image format. Buffer overflows or out-of-bound reads could lead to a denial of service (application crash) if a malformed image file is processed.

Gentoo Linux Security Advisory 202210-31

Gentoo Linux Security Advisory 202210-31 - Multiple vulnerabilities have been discovered in OpenEXR, the worst of which could result in arbitrary code execution. Versions less than 3.1.5 are affected.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907