Bugzilla – Bug 1173469
VUL-0: CVE-2020-15306: OpenEXR,openexr: invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize()
Last modified: 2020-07-23 07:03:54 UTC
CVE-2020-15306 An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15306 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-15306.html https://github.com/AcademySoftwareFoundation/openexr/pull/738 https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md https://github.com/AcademySoftwareFoundation/openexr/blob/master/SECURITY.md http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15306 https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.2
Fixed in TW by update to 2.5.2.
No reproducer found. 12,15/openexr: patch -- pull request referenced in comment 0 -- applies cleanly 11/OpenEXR: code not found
Will submit for 15,12/openexr. I believe all fixed.
SUSE-SU-2020:1931-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1173466,1173467,1173469 CVE References: CVE-2020-15304,CVE-2020-15305,CVE-2020-15306 Sources used: SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (src): openexr-2.2.1-3.18.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (src): openexr-2.2.1-3.18.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:0970-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1173466,1173467,1173469 CVE References: CVE-2020-15304,CVE-2020-15305,CVE-2020-15306 Sources used: openSUSE Leap 15.1 (src): openexr-2.2.1-lp151.4.12.1
openSUSE-SU-2020:1015-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1173466,1173467,1173469 CVE References: CVE-2020-15304,CVE-2020-15305,CVE-2020-15306 Sources used: openSUSE Leap 15.2 (src): openexr-2.2.1-lp152.7.5.1
SUSE-SU-2020:1984-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1173466,1173467,1173469 CVE References: CVE-2020-15304,CVE-2020-15305,CVE-2020-15306 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP5 (src): openexr-2.1.0-6.23.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): openexr-2.1.0-6.23.1 SUSE Linux Enterprise Server 12-SP5 (src): openexr-2.1.0-6.23.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Done