Jump to content

Advisories MDVSA-2009:191-1: OpenEXR


paul
 Share

Recommended Posts

Multiple vulnerabilities has been found and corrected in OpenEXR:

 

Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1

allow context-dependent attackers to cause a denial of service

(application crash) or possibly execute arbitrary code via unspecified

vectors that trigger heap-based buffer overflows, related to (1)

the Imf::PreviewImage::PreviewImage function and (2) compressor

constructors. NOTE: some of these details are obtained from third

party information (CVE-2009-1720).

 

The decompression implementation in the Imf::hufUncompress function in

OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a

denial of service (application crash) or possibly execute arbitrary

code via vectors that trigger a free of an uninitialized pointer

(CVE-2009-1721).

 

Buffer overflow in the compression implementation in OpenEXR 1.2.2

allows context-dependent attackers to cause a denial of service

(application crash) or possibly execute arbitrary code via unspecified

vectors (CVE-2009-1722).

 

This update provides fixes for these vulnerabilities.

 

Update:

 

Packages for 2008.0 are being provided due to extended support for

Corporate products.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...