Publishing details
Changelog
openexr (2.5.7-1) unstable; urgency=medium
* New upstream release
- debian/control: bump libilmbase-dev version
- debian/patches/series: drop CVE-2021-23169.diff
(applied upstream)
This release addresses following security issues:
+ CVE-2021-26260 and CVE-2021-23215
| An integer overflow leading to a heap-buffer overflow
| was found in the DwaCompressor of OpenEXR in versions
| before 3.0.1. An attacker could use this flaw to crash
| an application compiled with OpenEXR.
+ CVE-2021-3605 and CVE-2021-3598
| There's a flaw in OpenEXR's rleUncompress functionality
| in versions prior to 3.0.5. An attacker who is able to
| submit a crafted file to an application linked with
| OpenEXR could cause an out-of-bounds read.
| The greatest risk from this flaw is to application
| availability.
* debian/watch: change path and narrow down search
-- Matteo F. Vescovi <email address hidden> Sat, 28 Aug 2021 22:20:22 +0200
Builds
Built packages
-
libopenexr-dev
development files for the OpenEXR image library
-
libopenexr25
runtime files for the OpenEXR image library
-
libopenexr25-dbgsym
debug symbols for libopenexr25
-
openexr
command-line tools for the OpenEXR image format
-
openexr-dbgsym
debug symbols for openexr
-
openexr-doc
documentation and examples for the OpenEXR image format
Package files