LWN.net Logo

Fedora alert FEDORA-2009-8132 (OpenEXR)

From:  updates@fedoraproject.org
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora 11 Update: OpenEXR-1.6.1-8.fc11
Date:  Fri, 31 Jul 2009 18:01:21 +0000
Message-ID:  <20090731180121.E845A10F875@bastion2.fedora.phx.redhat.com>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8132 2009-07-31 17:30:13 -------------------------------------------------------------------------------- Name : OpenEXR Product : Fedora 11 Version : 1.6.1 Release : 8.fc11 URL : http://www.openexr.com/ Summary : A high dynamic-range (HDR) image file format Description : OpenEXR is a high dynamic-range (HDR) image file format developed by Industrial Light & Magic for use in computer imaging applications. This package contains libraries and sample applications for handling the format. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 29 2009 Rex Dieter <rdieter@fedoraproject.org> 1.6.1-8 - CVE-2009-1720 OpenEXR: Multiple integer overflows (#513995) - CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression (#514003) * Fri Jul 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.6.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #513995 - CVE-2009-1720 OpenEXR: Multiple integer overflows https://bugzilla.redhat.com/show_bug.cgi?id=513995 [ 2 ] Bug #514003 - CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression https://bugzilla.redhat.com/show_bug.cgi?id=514003 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update OpenEXR' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds