Advisories ยป MGASA-2019-0373

Updated openexr packages fix security vulnerability

Publication date: 08 Dec 2019
Modification date: 08 Dec 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2017-14988

Description

The updated packages fix a security vulnerability:

Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote
attackers to cause a denial of service (excessive memory allocation) via
a crafted file that is accessed with the ImfOpenInputFile function in
IlmImf/ImfCRgbaFile.cpp. (CVE-2017-14988)
                

References

SRPMS

7/core