QID 198318

Date Published: 2021-04-06

QID 198318: Ubuntu Security Notification for Openexr Vulnerabilities (USN-4900-1)

It was discovered that OpenEXR incorrectly handled certain malformed EXR image files.

If a user were tricked into opening a crafted EXR image file, a remote attacker could cause a denial of service, or possibly execute arbitrary code.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4900-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-4900-1 16.04 (Xenial) on src libopenexr22 URL Logo launchpad.net/ubuntu/+source/openexr/2.2.0-10ubuntu2.6
    USN-4900-1 16.04 (Xenial) on src openexr URL Logo launchpad.net/ubuntu/+source/openexr/2.2.0-10ubuntu2.6
    USN-4900-1 18.04 (bionic) on src libopenexr22 URL Logo launchpad.net/ubuntu/+source/openexr/2.2.0-11.1ubuntu1.6
    USN-4900-1 18.04 (bionic) on src openexr URL Logo launchpad.net/ubuntu/+source/openexr/2.2.0-11.1ubuntu1.6
    USN-4900-1 20.04 (focal) on src libopenexr24 URL Logo launchpad.net/ubuntu/+source/openexr/2.3.0-6ubuntu0.5
    USN-4900-1 20.04 (focal) on src openexr URL Logo launchpad.net/ubuntu/+source/openexr/2.3.0-6ubuntu0.5
    USN-4900-1 20.10 (groovy) on src libopenexr25 URL Logo launchpad.net/ubuntu/+source/openexr/2.5.3-2ubuntu0.2
    USN-4900-1 20.10 (groovy) on src openexr URL Logo launchpad.net/ubuntu/+source/openexr/2.5.3-2ubuntu0.2