Debian alert DLA-2701-1 (openexr)
| From: | Sylvain Beucler <beuc@beuc.net> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 2701-1] openexr security update | |
| Date: | Sat, 03 Jul 2021 20:16:01 +0200 | |
| Message-ID: | <20210703181601.GA20560@mail.beuc.net> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2701-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler July 03, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : openexr Version : 2.2.0-11+deb9u3 CVE ID : CVE-2020-16587 CVE-2021-3474 CVE-2021-3475 CVE-2021-3476 CVE-2021-3477 CVE-2021-3478 CVE-2021-3479 CVE-2021-3598 CVE-2021-20296 CVE-2021-23215 CVE-2021-26260 Debian Bug : 986796 990450 Several vulnerabilities were discovered in OpenEXR, a library and tools for the OpenEXR high dynamic-range (HDR) image format. An attacker could cause a denial of service (DoS) through application crash and excessive memory consumption. For Debian 9 stretch, these problems have been fixed in version 2.2.0-11+deb9u3. We recommend that you upgrade your openexr packages. For the detailed security status of openexr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openexr Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmDgqCIACgkQDTl9HeUl XjCBhg/7Bcqfg80BNKbiRGciy0QtJUjVK5qbFrr3eHfHD9daMZhq4cShlr0DiNlp pyVdPGoSgkSbCZYU92XHbRHKy3vVDEki/dFyvuUeCpETL2lyrBEwpN2isMSDZQQy HEtEQ+qtPRu0uUwnQsMdsHDMk4uVjBVvws4u5rJeaYwkMAEsERhIXF8rGMpSkves xGuhN8vyyU8FH5IycOjDsZgLuiZpwwF4tN2/P2gUA+8JVQeSt7V7wZPBhxO1qBuh FALwdldOdlvKKRf4g9PLXsA15E5jdJLuseYety9pq8qy5FsuwwkfZtMgypWXoFF3 ofP65tnyxebL7WRK+cLqgdQrbrJ61CSwVOrKqDsJoK+xM6dC1IYXuMIZu/1IEOBL XANLfxuHoTi9mQ4rlkghd306/xeXISe/dBRp50ae0W1P1VSLjt76VIDGkKPD3kGL Ykkg1fuvrvCIhCZdMLDLOeAbwJQyUjm3jLQ+9lrfzP6ycdB8CEEKvzsDu0E/VpGF 597NYu8npz0BVmKkd20aNS3XZP6Bokwiq7x0dE3SLG+A9Uh86HpzynMAwKqwtIJM UQXwYYSaEkx4rxgt0SphpuUPq0RcWzXEqQcS/vgH3U09smb27QYA/viEeHD+S+SC 78dLix8GOVYAGV/vGyVN50ZZMRjYbqZh/YNAypihmKQetHazo7s= =Umlk -----END PGP SIGNATURE-----
