Bugzilla – Bug 1219498
VUL-0: CVE-2023-5841: openexr: heap-based buffer overflow in generic_unpack_deep()
Last modified: 2024-04-19 08:31:02 UTC
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5841 https://www.cve.org/CVERecord?id=CVE-2023-5841 https://takeonme.org/cves/CVE-2023-5841.html
Tracking as affected: - SUSE:ALP:Source:Standard:1.0/openexr - openSUSE:Factory/openexr
https://github.com/AcademySoftwareFoundation/openexr/commit/46944c3a87ebc6c5d9a9a4962a94569ba1082bc3
Factory submission: https://build.opensuse.org/request/show/1144873 ALP submission: https://build.suse.de/request/show/320773
libdeflate -32bit version does not exist, openexr started to depend on it. Submission into devel project: https://build.opensuse.org/request/show/1145130
(In reply to Petr Gajdos from comment #5) > libdeflate -32bit version does not exist, openexr started to depend on it. > > Submission into devel project: > https://build.opensuse.org/request/show/1145130 https://build.opensuse.org/request/show/1146196
(In reply to Petr Gajdos from comment #6) > (In reply to Petr Gajdos from comment #5) > > libdeflate -32bit version does not exist, openexr started to depend on it. > > > > Submission into devel project: > > https://build.opensuse.org/request/show/1145130 > > https://build.opensuse.org/request/show/1146196 Submission into Factory: https://build.opensuse.org/request/show/1146390
openexr 3.2.2 is out https://build.opensuse.org/request/show/1146590
Factory sr is accepted, ALP pending. I believe all fixed.
Everything should be released, closing.