aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authorMatthias Andree <mandree@FreeBSD.org>2020-07-16 20:02:37 +0800
committerMatthias Andree <mandree@FreeBSD.org>2020-07-16 20:02:37 +0800
commitf02000691392d3bc3f76f6081c7d6e410728e69d (patch)
tree851da2e39cf7e9702f5cf212764d2a5dc0382454 /security
parentfad449e143232e3009d61629aa52e54a2af4223d (diff)
downloadfreebsd-ports-gnome-f02000691392d3bc3f76f6081c7d6e410728e69d.tar.gz
freebsd-ports-gnome-f02000691392d3bc3f76f6081c7d6e410728e69d.tar.zst
freebsd-ports-gnome-f02000691392d3bc3f76f6081c7d6e410728e69d.zip
vuln db: record OpenEXR/ilmbase < 2.5.2 vulnerabilities
Security: 714e6c35-c75b-11ea-aa29-d74973d1f9f3
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml34
1 files changed, 34 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 246182be6bef..65052c7c99ed 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -58,6 +58,40 @@ Notes:
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="714e6c35-c75b-11ea-aa29-d74973d1f9f3">
+ <topic>OpenEXR/ilmbase 2.5.2 -- patch release with various bug/security fixes</topic>
+ <affects>
+ <package>
+ <name>ilmbase</name>
+ <range><lt>2.5.2</lt></range>
+ </package>
+ <package>
+ <name>openexr</name>
+ <range><lt>2.5.2</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Cary Phillips reports:</p>
+ <blockquote cite="https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.2">
+ <p>openexr 2.5.2 [is a p]atch release with various bug/security and build/install fixes:</p>
+ <ul>
+ <li>Invalid input could cause a heap-use-after-free error in DeepScanLineInputFile::DeepScanLineInputFile()</li>
+ <li>Invalid chunkCount attributes could cause heap buffer overflow in getChunkOffsetTableSize()</li>
+ <li>Invalid tiled input file could cause invalid memory access TiledInputFile::TiledInputFile()</li>
+ </ul>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.2</url>
+ </references>
+ <dates>
+ <discovery>2020-05-18</discovery>
+ <entry>2020-07-16</entry>
+ </dates>
+ </vuln>
+
<vuln vid="870d59b0-c6c4-11ea-8015-e09467587c17">
<topic>chromium -- multiple vulnerabilities</topic>
<affects>