[ubuntu/eoan-proposed] openexr 2.2.1-4.1ubuntu1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Oct 3 18:37:28 UTC 2019


openexr (2.2.1-4.1ubuntu1) eoan; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2017-911x-2.patch: address pointer overflows in
      IlmImf/ImfScanLineInputFile.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp.
    - debian/patches/CVE-2017-911x-3.patch: merge common fixes and move
      bounds check to central location in IlmImf/ImfFrameBuffer.h,
      IlmImf/ImfHeader.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp, exrmaketiled/Image.h,
      exrmultiview/Image.h.
    - debian/patches/CVE-2017-911x-4.patch: refactor origin function to a
      Slice factory and Rgba custom utility in IlmImf/ImfFrameBuffer.cpp,
      IlmImf/ImfFrameBuffer.h, IlmImf/ImfRgbaFile.h,
      exrenvmap/readInputImage.cpp, exrmakepreview/makePreview.cpp,
      exrmaketiled/Image.h, exrmultiview/Image.h.
    - CVE-2017-9111
    - CVE-2017-9113
    - CVE-2017-9115
    - CVE-2018-18444

Date: Wed, 02 Oct 2019 13:01:44 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/openexr/2.2.1-4.1ubuntu1
-------------- next part --------------
Format: 1.8
Date: Wed, 02 Oct 2019 13:01:44 -0400
Source: openexr
Architecture: source
Version: 2.2.1-4.1ubuntu1
Distribution: eoan
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 openexr (2.2.1-4.1ubuntu1) eoan; urgency=medium
 .
   * SECURITY UPDATE: Multiple security issues
     - debian/patches/CVE-2017-911x-2.patch: address pointer overflows in
       IlmImf/ImfScanLineInputFile.cpp, exrenvmap/readInputImage.cpp,
       exrmakepreview/makePreview.cpp.
     - debian/patches/CVE-2017-911x-3.patch: merge common fixes and move
       bounds check to central location in IlmImf/ImfFrameBuffer.h,
       IlmImf/ImfHeader.cpp, exrenvmap/readInputImage.cpp,
       exrmakepreview/makePreview.cpp, exrmaketiled/Image.h,
       exrmultiview/Image.h.
     - debian/patches/CVE-2017-911x-4.patch: refactor origin function to a
       Slice factory and Rgba custom utility in IlmImf/ImfFrameBuffer.cpp,
       IlmImf/ImfFrameBuffer.h, IlmImf/ImfRgbaFile.h,
       exrenvmap/readInputImage.cpp, exrmakepreview/makePreview.cpp,
       exrmaketiled/Image.h, exrmultiview/Image.h.
     - CVE-2017-9111
     - CVE-2017-9113
     - CVE-2017-9115
     - CVE-2018-18444
Checksums-Sha1:
 aa5cdd1e0ff662df49e4284a7da13465caf3f2f6 2377 openexr_2.2.1-4.1ubuntu1.dsc
 cc5c9eb46ac78fd379021ac3239c76c940d4cc66 22508 openexr_2.2.1-4.1ubuntu1.debian.tar.xz
 f474fbfc0c0f5618a737412bca6c3841255158af 5779 openexr_2.2.1-4.1ubuntu1_source.buildinfo
Checksums-Sha256:
 b85994b01154c6af482ab06c7dba782395c29fc830c68810c39dd95992bb6466 2377 openexr_2.2.1-4.1ubuntu1.dsc
 ec4517647154f86430af15e101537d4d06eea71bc6918f0d6f7bf95fddfbce81 22508 openexr_2.2.1-4.1ubuntu1.debian.tar.xz
 4739b9facc9c3df2e850136cd927c16993fcc16d80732783df73e5fcf1df0732 5779 openexr_2.2.1-4.1ubuntu1_source.buildinfo
Files:
 6c92066eccd6512cb8fc9d9860141b37 2377 graphics optional openexr_2.2.1-4.1ubuntu1.dsc
 6a0f91dca0dc9b4365c9244802867b98 22508 graphics optional openexr_2.2.1-4.1ubuntu1.debian.tar.xz
 2be7964aa7b7d23eaa990301cb2a6013 5779 graphics optional openexr_2.2.1-4.1ubuntu1_source.buildinfo
Original-Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel at lists.alioth.debian.org>


More information about the Eoan-changes mailing list