QID 198318
Date Published: 2021-04-06
QID 198318: Ubuntu Security Notification for Openexr Vulnerabilities (USN-4900-1)
It was discovered that OpenEXR incorrectly handled certain malformed EXR image files.
If a user were tricked into opening a crafted EXR image file, a remote attacker could cause a denial of service, or possibly execute arbitrary code.
Solution
Refer to Ubuntu advisory USN-4900-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4900-1 -
usn.ubuntu.com/4900-1/
CVEs related to QID 198318
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4900-1 | 16.04 (Xenial) on src | libopenexr22 |
|
| USN-4900-1 | 16.04 (Xenial) on src | openexr |
|
| USN-4900-1 | 18.04 (bionic) on src | libopenexr22 |
|
| USN-4900-1 | 18.04 (bionic) on src | openexr |
|
| USN-4900-1 | 20.04 (focal) on src | libopenexr24 |
|
| USN-4900-1 | 20.04 (focal) on src | openexr |
|
| USN-4900-1 | 20.10 (groovy) on src | libopenexr25 |
|
| USN-4900-1 | 20.10 (groovy) on src | openexr |
|