Advisories ยป MGASA-2021-0326

Updated openexr packages fix security vulnerabilities

Publication date: 10 Jul 2021
Modification date: 10 Jul 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-3474 , CVE-2021-3475 , CVE-2021-3476 , CVE-2021-3477 , CVE-2021-3478 , CVE-2021-3479 , CVE-2021-3598 , CVE-2021-3605 , CVE-2021-20296 , CVE-2021-23169 , CVE-2021-23215 , CVE-2021-26260

Description

Updated openexr packages fix security vulnerabilities:

It was discovered that OpenEXR incorrectly handled certain malformed EXR
image files. If a user were tricked into opening a crafted EXR image file,
a remote attacker could cause a denial of service, or possibly execute
arbitrary code (CVE-2021-3474, CVE-2021-3475, CVE-2021-3476, CVE-2021-3477,
CVE-2021-3478, CVE-2021-3479, CVE-2021-3598, CVE-2021-3605, CVE-2021-20296,
CVE-2021-23169, CVE-2021-23215, CVE-2021-26260).
                

References

SRPMS

8/core

7/core