Publishing details

Changelog

openexr (2.5.7-1) unstable; urgency=medium

  * New upstream release
    - debian/control: bump libilmbase-dev version
    - debian/patches/series: drop CVE-2021-23169.diff
      (applied upstream)
    This release addresses following security issues:
    + CVE-2021-26260 and CVE-2021-23215
    | An integer overflow leading to a heap-buffer overflow
    | was found in the DwaCompressor of OpenEXR in versions
    | before 3.0.1. An attacker could use this flaw to crash
    | an application compiled with OpenEXR.
    + CVE-2021-3605 and CVE-2021-3598
    | There's a flaw in OpenEXR's rleUncompress functionality
    | in versions prior to 3.0.5. An attacker who is able to
    | submit a crafted file to an application linked with
    | OpenEXR could cause an out-of-bounds read.
    | The greatest risk from this flaw is to application
    | availability.
  * debian/watch: change path and narrow down search

 -- Matteo F. Vescovi <email address hidden>  Sat, 28 Aug 2021 22:20:22 +0200

Available diffs

Builds

Built packages

Package files