Change log for openexr package in Ubuntu

150 of 72 results
Published in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
openexr (3.1.5-5.1) unstable; urgency=low

  * Non-maintainer upload.
  * Add upstream fix for FTBFS with gcc 13. (Closes: #1037801)

 -- Adrian Bunk <email address hidden>  Fri, 11 Aug 2023 00:09:40 +0300

Available diffs

Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
openexr (3.1.5-5) unstable; urgency=medium

  * Team upload.

  [ Andreas Metzler ]
  * Make versioning of libilmbase-dev Breaks/Replaces binNMU-safe.
    (Closes: #1033617)

  [ Matteo F. Vescovi ]
  * debian/control: S-V bump 4.6.1 -> 4.6.2 (no changes needed)

 -- Matteo F. Vescovi <email address hidden>  Sun, 23 Apr 2023 18:46:33 +0200

Available diffs

Superseded in mantic-release
Published in lunar-release
Published in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
openexr (3.1.5-4) unstable; urgency=medium

  * d/control: Add missing zlib1g-dev dependency. Closes: #1017516
  * d/control: Run wrap-and-sort
  * d/control: Bump Std-Vers to 4.6.1 no changes needed

 -- Mathieu Malaterre <email address hidden>  Wed, 17 Aug 2022 12:44:50 +0200

Available diffs

Superseded in kinetic-proposed
openexr (3.1.5-3) unstable; urgency=medium

  * d/control: Add missing Breaks/Replaces on libilmbase-dev. Closes: #1009308

 -- Mathieu Malaterre <email address hidden>  Wed, 17 Aug 2022 09:32:51 +0200

Available diffs

Superseded in kinetic-proposed
openexr (3.1.5-2) unstable; urgency=medium

  * Upload to unstable.

 -- Mathieu Malaterre <email address hidden>  Tue, 16 Aug 2022 18:52:29 +0200
Published in bionic-updates
Published in bionic-security
openexr (2.2.0-11.1ubuntu1.9) bionic-security; urgency=medium

  * SECURITY UPDATE: Divide-by-zero
    - debian/patches/CVE-2021-3941-*.patch: stop div by zero
      by catching bad chromaticities in IlmImf/ImfChromaticities.cpp.
    - CVE-2021-3941

 -- Leonidas Da Silva Barbosa <email address hidden>  Tue, 16 Nov 2021 12:51:38 -0300
Superseded in bionic-updates
Superseded in bionic-security
openexr (2.2.0-11.1ubuntu1.8) bionic-security; urgency=medium

  * SECURITY UPDATE: Integer overflow
    - debian/patches/CVE-2021-3933.patch: prevent overflow
      in bytesPerDeepLineTable in IlmImf/ImfMisc.cpp.
    - CVE-2021-3933

 -- Leonidas Da Silva Barbosa <email address hidden>  Wed, 10 Nov 2021 10:32:47 -0300
Superseded in kinetic-release
Published in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
openexr (2.5.7-1) unstable; urgency=medium

  * New upstream release
    - debian/control: bump libilmbase-dev version
    - debian/patches/series: drop CVE-2021-23169.diff
      (applied upstream)
    This release addresses following security issues:
    + CVE-2021-26260 and CVE-2021-23215
    | An integer overflow leading to a heap-buffer overflow
    | was found in the DwaCompressor of OpenEXR in versions
    | before 3.0.1. An attacker could use this flaw to crash
    | an application compiled with OpenEXR.
    + CVE-2021-3605 and CVE-2021-3598
    | There's a flaw in OpenEXR's rleUncompress functionality
    | in versions prior to 3.0.5. An attacker who is able to
    | submit a crafted file to an application linked with
    | OpenEXR could cause an out-of-bounds read.
    | The greatest risk from this flaw is to application
    | availability.
  * debian/watch: change path and narrow down search

 -- Matteo F. Vescovi <email address hidden>  Sat, 28 Aug 2021 22:20:22 +0200

Available diffs

Superseded in bionic-updates
Superseded in bionic-security
openexr (2.2.0-11.1ubuntu1.7) bionic-security; urgency=medium

  * SECURITY UPDATE: Heap-buffer-overflow in function readChars
    - debian/patches/CVE-2021-3598.patch: verify data size in deepscanlines
      with NO_COMPRESSION in IlmImf/ImfDeepScanLineInputFile.cpp.
    - CVE-2021-3598
  * SECURITY UPDATE: Heap buffer overflow in the rleUncompress function
    - debian/patches/CVE-2021-3605.patch: detect buffer overflows in
      IlmImf/ImfRle.cpp.
    - CVE-2021-3605
  * SECURITY UPDATE: null deref in Dwa decompression
    - debian/patches/CVE-2021-20296.patch: double-check unpackedBuffer
      created in DWA uncompress in IlmImf/ImfDwaCompressor.cpp.
    - CVE-2021-20296
  * SECURITY UPDATE: heap overflow in DwaCompressor
    - debian/patches/CVE-2021-23215-pre1.patch: switch over to use
      compressBound() instead of manually computing headroom for compress()
      in IlmImf/ImfDwaCompressor.cpp.
    - debian/patches/CVE-2021-23215.patch: use size_t for DWA buffersize
      calculation in IlmImf/ImfDwaCompressor.cpp.
    - CVE-2021-23215
  * SECURITY UPDATE: heap overflow in DwaCompressor
    - debian/patches/CVE-2021-26260.patch: prevent int overflow in
      buffersize calculation in IlmImf/ImfDwaCompressor.cpp.
    - CVE-2021-26260

 -- Marc Deslauriers <email address hidden>  Mon, 21 Jun 2021 11:40:58 -0400
Superseded in jammy-release
Obsolete in impish-release
Deleted in impish-proposed (Reason: Moved to impish)
openexr (2.5.4-2) unstable; urgency=high

  * debian/patches/: patchset updated
    - CVE-2021-23169.diff added (Closes: #988240)
    | This patch aims to fix CVE-2021-23169:
    |   Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
    | The patch applied is a reduced version of the upstream
    | commit, given the code base has changed in the meanwhile.

 -- Matteo F. Vescovi <email address hidden>  Tue, 18 May 2021 23:26:12 +0200

Available diffs

Published in xenial-updates
Published in xenial-security
openexr (2.2.0-10ubuntu2.6) xenial-security; urgency=medium

  * SECURITY UPDATE: shift overflow in FastHufDecoder
    - debian/patches/CVE-2021-3474.patch: compute Huf codelengths using 64
      bit to prevent shift overflow in IlmImf/ImfFastHuf.cpp.
    - CVE-2021-3474
  * SECURITY UPDATE: integer overflow in calculateNumTiles
    - debian/patches/CVE-2021-3475.patch: compute level size with 64 bits
      to avoid overflow in IlmImf/ImfTiledMisc.cpp.
    - CVE-2021-3475
  * SECURITY UPDATE: shift overflows
    - debian/patches/CVE-2021-3476.patch: ignore unused bits in B44 mode
      detection in IlmImf/ImfB44Compressor.cpp.
    - CVE-2021-3476
  * SECURITY UPDATE: out-of-bounds read via deep tile sample size
    - debian/patches/CVE-2021-3477.patch: fix overflow computing deeptile
      sample table size in IlmImf/ImfDeepTiledInputFile.cpp.
    - CVE-2021-3477
  * SECURITY UPDATE: memory consumption via input file
    - debian/patches/CVE-2021-3478-pre1.patch: reduce size limit for
      scanline files; prevent large chunkoffset allocations in
      IlmImf/ImfCompressor.cpp, IlmImf/ImfCompressor.h, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMultiPartInputFile.cpp, IlmImf/ImfScanLineInputFile.cpp.
    - debian/patches/CVE-2021-3478.patch: sanity check ScanlineInput
      bytesPerLine instead of lineOffset size in
      IlmImf/ImfScanLineInputFile.cpp.
    - CVE-2021-3478
  * SECURITY UPDATE: memory consumption in scanline API
    - debian/patches/CVE-2021-3479-pre1.patch: address issues reported by
      Undefined Behavior Sanitizer in IlmImf/ImfInputFile.cpp.
    - debian/patches/CVE-2021-3479.patch: more efficient handling of filled
      channels reading tiles with scanline API in IlmImf/ImfInputFile.cpp,
      IlmImfTest/testScanLineApi.cpp.
    - CVE-2021-3479

 -- Marc Deslauriers <email address hidden>  Thu, 01 Apr 2021 08:47:09 -0400
Superseded in bionic-updates
Superseded in bionic-security
openexr (2.2.0-11.1ubuntu1.6) bionic-security; urgency=medium

  * SECURITY UPDATE: shift overflow in FastHufDecoder
    - debian/patches/CVE-2021-3474.patch: compute Huf codelengths using 64
      bit to prevent shift overflow in IlmImf/ImfFastHuf.cpp.
    - CVE-2021-3474
  * SECURITY UPDATE: integer overflow in calculateNumTiles
    - debian/patches/CVE-2021-3475.patch: compute level size with 64 bits
      to avoid overflow in IlmImf/ImfTiledMisc.cpp.
    - CVE-2021-3475
  * SECURITY UPDATE: shift overflows
    - debian/patches/CVE-2021-3476.patch: ignore unused bits in B44 mode
      detection in IlmImf/ImfB44Compressor.cpp.
    - CVE-2021-3476
  * SECURITY UPDATE: out-of-bounds read via deep tile sample size
    - debian/patches/CVE-2021-3477.patch: fix overflow computing deeptile
      sample table size in IlmImf/ImfDeepTiledInputFile.cpp.
    - CVE-2021-3477
  * SECURITY UPDATE: memory consumption via input file
    - debian/patches/CVE-2021-3478-pre1.patch: reduce size limit for
      scanline files; prevent large chunkoffset allocations in
      IlmImf/ImfCompressor.cpp, IlmImf/ImfCompressor.h, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMultiPartInputFile.cpp, IlmImf/ImfScanLineInputFile.cpp.
    - debian/patches/CVE-2021-3478.patch: sanity check ScanlineInput
      bytesPerLine instead of lineOffset size in
      IlmImf/ImfScanLineInputFile.cpp.
    - CVE-2021-3478
  * SECURITY UPDATE: memory consumption in scanline API
    - debian/patches/CVE-2021-3479-pre1.patch: address issues reported by
      Undefined Behavior Sanitizer in IlmImf/ImfInputFile.cpp.
    - debian/patches/CVE-2021-3479.patch: more efficient handling of filled
      channels reading tiles with scanline API in IlmImf/ImfInputFile.cpp,
      IlmImfTest/testScanLineApi.cpp.
    - CVE-2021-3479

 -- Marc Deslauriers <email address hidden>  Thu, 01 Apr 2021 08:47:09 -0400
Published in focal-updates
Published in focal-security
openexr (2.3.0-6ubuntu0.5) focal-security; urgency=medium

  * SECURITY UPDATE: shift overflow in FastHufDecoder
    - debian/patches/CVE-2021-3474.patch: compute Huf codelengths using 64
      bit to prevent shift overflow in IlmImf/ImfFastHuf.cpp.
    - CVE-2021-3474
  * SECURITY UPDATE: integer overflow in calculateNumTiles
    - debian/patches/CVE-2021-3475.patch: compute level size with 64 bits
      to avoid overflow in IlmImf/ImfTiledMisc.cpp.
    - CVE-2021-3475
  * SECURITY UPDATE: shift overflows
    - debian/patches/CVE-2021-3476.patch: ignore unused bits in B44 mode
      detection in IlmImf/ImfB44Compressor.cpp.
    - CVE-2021-3476
  * SECURITY UPDATE: out-of-bounds read via deep tile sample size
    - debian/patches/CVE-2021-3477.patch: fix overflow computing deeptile
      sample table size in IlmImf/ImfDeepTiledInputFile.cpp.
    - CVE-2021-3477
  * SECURITY UPDATE: memory consumption via input file
    - debian/patches/CVE-2021-3478-pre1.patch: reduce size limit for
      scanline files; prevent large chunkoffset allocations in
      IlmImf/ImfCompressor.cpp, IlmImf/ImfCompressor.h, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMultiPartInputFile.cpp, IlmImf/ImfScanLineInputFile.cpp.
    - debian/patches/CVE-2021-3478.patch: sanity check ScanlineInput
      bytesPerLine instead of lineOffset size in
      IlmImf/ImfScanLineInputFile.cpp.
    - CVE-2021-3478
  * SECURITY UPDATE: memory consumption in scanline API
    - debian/patches/CVE-2021-3479-pre1.patch: address issues reported by
      Undefined Behavior Sanitizer in IlmImf/ImfInputFile.cpp.
    - debian/patches/CVE-2021-3479.patch: more efficient handling of filled
      channels reading tiles with scanline API in IlmImf/ImfInputFile.cpp,
      IlmImfTest/testScanLineApi.cpp.
    - CVE-2021-3479

 -- Marc Deslauriers <email address hidden>  Thu, 01 Apr 2021 08:47:09 -0400
Obsolete in groovy-updates
Obsolete in groovy-security
openexr (2.5.3-2ubuntu0.2) groovy-security; urgency=medium

  * SECURITY UPDATE: shift overflow in FastHufDecoder
    - debian/patches/CVE-2021-3474.patch: compute Huf codelengths using 64
      bit to prevent shift overflow in OpenEXR/IlmImf/ImfFastHuf.cpp.
    - CVE-2021-3474
  * SECURITY UPDATE: integer overflow in calculateNumTiles
    - debian/patches/CVE-2021-3475.patch: compute level size with 64 bits
      to avoid overflow in OpenEXR/IlmImf/ImfTiledMisc.cpp.
    - CVE-2021-3475
  * SECURITY UPDATE: shift overflows
    - debian/patches/CVE-2021-3476.patch: ignore unused bits in B44 mode
      detection in OpenEXR/IlmImf/ImfB44Compressor.cpp.
    - CVE-2021-3476
  * SECURITY UPDATE: out-of-bounds read via deep tile sample size
    - debian/patches/CVE-2021-3477.patch: fix overflow computing deeptile
      sample table size in OpenEXR/IlmImf/ImfDeepTiledInputFile.cpp.
    - CVE-2021-3477
  * SECURITY UPDATE: memory consumption via input file
    - debian/patches/CVE-2021-3478-pre1.patch: reduce size limit for
      scanline files; prevent large chunkoffset allocations in
      OpenEXR/IlmImf/ImfCompressor.cpp, OpenEXR/IlmImf/ImfCompressor.h,
      OpenEXR/IlmImf/ImfMisc.cpp, OpenEXR/IlmImf/ImfMisc.h,
      OpenEXR/IlmImf/ImfMultiPartInputFile.cpp,
      OpenEXR/IlmImf/ImfScanLineInputFile.cpp.
    - debian/patches/CVE-2021-3478.patch: sanity check ScanlineInput
      bytesPerLine instead of lineOffset size in
      OpenEXR/IlmImf/ImfScanLineInputFile.cpp.
    - CVE-2021-3478
  * SECURITY UPDATE: memory consumption in scanline API
    - debian/patches/CVE-2021-3479-pre1.patch: address issues reported by
      Undefined Behavior Sanitizer in OpenEXR/IlmImf/ImfInputFile.cpp.
    - debian/patches/CVE-2021-3479.patch: more efficient handling of filled
      channels reading tiles with scanline API in
      OpenEXR/IlmImf/ImfInputFile.cpp,
      OpenEXR/IlmImfTest/testScanLineApi.cpp.
    - CVE-2021-3479

 -- Marc Deslauriers <email address hidden>  Thu, 01 Apr 2021 08:47:09 -0400
Superseded in impish-release
Obsolete in hirsute-release
Deleted in hirsute-proposed (Reason: moved to Release)
openexr (2.5.4-1) unstable; urgency=medium

  * New upstream release
  * debian/watch: parameters updated
  * debian/control:
    - S-V bump 4.5.0 -> 4.5.1 (no changes needed)
    - set minimal ilmbase lib to v2.5.4

 -- Matteo F. Vescovi <email address hidden>  Thu, 21 Jan 2021 23:24:00 +0100

Available diffs

Superseded in bionic-updates
Superseded in bionic-security
openexr (2.2.0-11.1ubuntu1.4) bionic-security; urgency=medium

  * SECURITY UPDATE: DoS via heap overflow in chunkOffsetReconstruction
    - debian/patches/CVE-2020-16587.patch: properly check chunk offset in
      IlmImf/ImfMultiPartInputFile.cpp.
    - CVE-2020-16587
  * SECURITY UPDATE: DoS via null pointer dereference
    - debian/patches/CVE-2020-16588.patch: fix logic for 1 pixel high/wide
      preview images in exrmakepreview/makePreview.cpp.
    - CVE-2020-16588
  * SECURITY UPDATE: DoS via heap overflow in writeTileData
    - debian/patches/CVE-2020-16589.patch: validate tile coordinates when
      doing copyPixels in IlmImf/ImfTiledInputFile.cpp.
    - CVE-2020-16589

 -- Marc Deslauriers <email address hidden>  Fri, 11 Dec 2020 08:26:23 -0500
Superseded in xenial-updates
Superseded in xenial-security
openexr (2.2.0-10ubuntu2.4) xenial-security; urgency=medium

  * SECURITY UPDATE: DoS via heap overflow in chunkOffsetReconstruction
    - debian/patches/CVE-2020-16587.patch: properly check chunk offset in
      IlmImf/ImfMultiPartInputFile.cpp.
    - CVE-2020-16587
  * SECURITY UPDATE: DoS via null pointer dereference
    - debian/patches/CVE-2020-16588.patch: fix logic for 1 pixel high/wide
      preview images in exrmakepreview/makePreview.cpp.
    - CVE-2020-16588
  * SECURITY UPDATE: DoS via heap overflow in writeTileData
    - debian/patches/CVE-2020-16589.patch: validate tile coordinates when
      doing copyPixels in IlmImf/ImfTiledInputFile.cpp.
    - CVE-2020-16589

 -- Marc Deslauriers <email address hidden>  Fri, 11 Dec 2020 08:27:00 -0500
Superseded in focal-updates
Superseded in focal-security
openexr (2.3.0-6ubuntu0.3) focal-security; urgency=medium

  * SECURITY UPDATE: DoS via heap overflow in chunkOffsetReconstruction
    - debian/patches/CVE-2020-16587.patch: properly check chunk offset in
      IlmImf/ImfMultiPartInputFile.cpp.
    - CVE-2020-16587
  * SECURITY UPDATE: DoS via null pointer dereference
    - debian/patches/CVE-2020-16588.patch: fix logic for 1 pixel high/wide
      preview images in exrmakepreview/makePreview.cpp.
    - CVE-2020-16588
  * SECURITY UPDATE: DoS via heap overflow in writeTileData
    - debian/patches/CVE-2020-16589.patch: validate tile coordinates when
      doing copyPixels in IlmImf/ImfTiledInputFile.cpp.
    - CVE-2020-16589

 -- Marc Deslauriers <email address hidden>  Fri, 11 Dec 2020 08:20:43 -0500
Superseded in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
openexr (2.3.0-6ubuntu3) groovy; urgency=medium

  * Rebuild against new ilmbase.

 -- Gianfranco Costamagna <email address hidden>  Thu, 03 Sep 2020 14:14:23 +0200
Superseded in groovy-proposed
openexr (2.3.0-6ubuntu2) groovy; urgency=medium

  * No change rebuild against new ilmbase ABI.

 -- Dimitri John Ledkov <email address hidden>  Fri, 28 Aug 2020 14:10:53 +0100

Available diffs

Superseded in hirsute-release
Obsolete in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
openexr (2.5.3-2) unstable; urgency=medium

  * Upload to unstable (Closes: #959444)

 -- Matteo F. Vescovi <email address hidden>  Fri, 21 Aug 2020 22:56:55 +0200
Superseded in bionic-updates
Superseded in bionic-security
openexr (2.2.0-11.1ubuntu1.3) bionic-security; urgency=medium

  * SECURITY UPDATE: use-after-free in DeepScanLineInputFile
    - debian/patches/CVE-2020-15305.patch: add missing throw in
      deepscanline error handling in IlmImf/ImfDeepScanLineInputFile.cpp.
    - CVE-2020-15305
  * SECURITY UPDATE: heap buffer overflow in getChunkOffsetTableSize()
    - debian/patches/CVE-2020-15306.patch: always ignore chunkCount
      attribute unless it cannot be computed in
      IlmImf/ImfDeepTiledOutputFile.cpp, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMisc.h, IlmImf/ImfMultiPartInputFile.cpp,
      IlmImf/ImfMultiPartOutputFile.cpp.
    - CVE-2020-15306

 -- Marc Deslauriers <email address hidden>  Tue, 30 Jun 2020 14:24:10 -0400
Obsolete in eoan-updates
Obsolete in eoan-security
openexr (2.2.1-4.1ubuntu1.2) eoan-security; urgency=medium

  * SECURITY UPDATE: use-after-free in DeepScanLineInputFile
    - debian/patches/CVE-2020-15305.patch: add missing throw in
      deepscanline error handling in IlmImf/ImfDeepScanLineInputFile.cpp.
    - CVE-2020-15305
  * SECURITY UPDATE: heap buffer overflow in getChunkOffsetTableSize()
    - debian/patches/CVE-2020-15306.patch: always ignore chunkCount
      attribute unless it cannot be computed in
      IlmImf/ImfDeepTiledOutputFile.cpp, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMisc.h, IlmImf/ImfMultiPartInputFile.cpp,
      IlmImf/ImfMultiPartOutputFile.cpp.
    - CVE-2020-15306

 -- Marc Deslauriers <email address hidden>  Tue, 30 Jun 2020 14:23:38 -0400
Superseded in xenial-updates
Superseded in xenial-security
openexr (2.2.0-10ubuntu2.3) xenial-security; urgency=medium

  * SECURITY UPDATE: use-after-free in DeepScanLineInputFile
    - debian/patches/CVE-2020-15305.patch: add missing throw in
      deepscanline error handling in IlmImf/ImfDeepScanLineInputFile.cpp.
    - CVE-2020-15305
  * SECURITY UPDATE: heap buffer overflow in getChunkOffsetTableSize()
    - debian/patches/CVE-2020-15306.patch: always ignore chunkCount
      attribute unless it cannot be computed in
      IlmImf/ImfDeepTiledOutputFile.cpp, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMisc.h, IlmImf/ImfMultiPartInputFile.cpp,
      IlmImf/ImfMultiPartOutputFile.cpp.
    - CVE-2020-15306

 -- Marc Deslauriers <email address hidden>  Tue, 30 Jun 2020 14:24:45 -0400
Superseded in focal-updates
Superseded in focal-security
openexr (2.3.0-6ubuntu0.2) focal-security; urgency=medium

  * SECURITY UPDATE: use-after-free in DeepScanLineInputFile
    - debian/patches/CVE-2020-15305.patch: add missing throw in
      deepscanline error handling in IlmImf/ImfDeepScanLineInputFile.cpp.
    - CVE-2020-15305
  * SECURITY UPDATE: heap buffer overflow in getChunkOffsetTableSize()
    - debian/patches/CVE-2020-15306.patch: always ignore chunkCount
      attribute unless it cannot be computed in
      IlmImf/ImfDeepTiledOutputFile.cpp, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMisc.h, IlmImf/ImfMultiPartInputFile.cpp,
      IlmImf/ImfMultiPartOutputFile.cpp.
    - CVE-2020-15306

 -- Marc Deslauriers <email address hidden>  Tue, 30 Jun 2020 13:24:21 -0400
Superseded in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
openexr (2.3.0-6ubuntu1) groovy; urgency=medium

  * SECURITY UPDATE: use-after-free in DeepScanLineInputFile
    - debian/patches/CVE-2020-15305.patch: add missing throw in
      deepscanline error handling in IlmImf/ImfDeepScanLineInputFile.cpp.
    - CVE-2020-15305
  * SECURITY UPDATE: heap buffer overflow in getChunkOffsetTableSize()
    - debian/patches/CVE-2020-15306.patch: always ignore chunkCount
      attribute unless it cannot be computed in
      IlmImf/ImfDeepTiledOutputFile.cpp, IlmImf/ImfMisc.cpp,
      IlmImf/ImfMisc.h, IlmImf/ImfMultiPartInputFile.cpp,
      IlmImf/ImfMultiPartOutputFile.cpp.
    - CVE-2020-15306

 -- Marc Deslauriers <email address hidden>  Tue, 30 Jun 2020 13:24:21 -0400
Superseded in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
Superseded in focal-updates
Superseded in focal-security
openexr (2.3.0-6ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2020-117xx/*.patch: backported multiple upstream
      commits to fix a multitude of issues.
    - CVE-2020-11758
    - CVE-2020-11759
    - CVE-2020-11760
    - CVE-2020-11761
    - CVE-2020-11762
    - CVE-2020-11763
    - CVE-2020-11764
    - CVE-2020-11765
  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2017-911x-2.patch: address pointer overflows in
      IlmImf/ImfScanLineInputFile.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp.
    - debian/patches/CVE-2017-911x-3.patch: merge common fixes and move
      bounds check to central location in IlmImf/ImfFrameBuffer.h,
      IlmImf/ImfHeader.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp, exrmaketiled/Image.h,
      exrmultiview/Image.h.
    - debian/patches/CVE-2017-911x-4.patch: refactor origin function to a
      Slice factory and Rgba custom utility in IlmImf/ImfFrameBuffer.cpp,
      IlmImf/ImfFrameBuffer.h, IlmImf/ImfRgbaFile.h,
      exrenvmap/readInputImage.cpp, exrmakepreview/makePreview.cpp,
      exrmaketiled/Image.h, exrmultiview/Image.h.
    - CVE-2017-9111
    - CVE-2017-9113
    - CVE-2017-9115
    - CVE-2018-18444

 -- Marc Deslauriers <email address hidden>  Thu, 23 Apr 2020 13:32:15 -0400
Superseded in eoan-updates
Superseded in eoan-security
openexr (2.2.1-4.1ubuntu1.1) eoan-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2020-117xx/*.patch: backported multiple upstream
      commits to fix a multitude of issues.
    - CVE-2020-11758
    - CVE-2020-11759
    - CVE-2020-11760
    - CVE-2020-11761
    - CVE-2020-11762
    - CVE-2020-11763
    - CVE-2020-11764
    - CVE-2020-11765

 -- Marc Deslauriers <email address hidden>  Thu, 23 Apr 2020 15:25:33 -0400
Superseded in bionic-updates
Superseded in bionic-security
openexr (2.2.0-11.1ubuntu1.2) bionic-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2020-117xx/*.patch: backported multiple upstream
      commits to fix a multitude of issues.
    - CVE-2020-11758
    - CVE-2020-11759
    - CVE-2020-11760
    - CVE-2020-11761
    - CVE-2020-11762
    - CVE-2020-11763
    - CVE-2020-11764
    - CVE-2020-11765

 -- Marc Deslauriers <email address hidden>  Fri, 24 Apr 2020 07:31:18 -0400
Superseded in xenial-updates
Superseded in xenial-security
openexr (2.2.0-10ubuntu2.2) xenial-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2020-117xx/*.patch: backported multiple upstream
      commits to fix a multitude of issues.
    - CVE-2020-11758
    - CVE-2020-11759
    - CVE-2020-11760
    - CVE-2020-11761
    - CVE-2020-11762
    - CVE-2020-11763
    - CVE-2020-11764
    - CVE-2020-11765

 -- Marc Deslauriers <email address hidden>  Fri, 24 Apr 2020 07:32:37 -0400
Superseded in groovy-release
Published in focal-release
Deleted in focal-proposed (Reason: moved to Release)
openexr (2.3.0-6build1) focal; urgency=medium

  * No-change rebuild for libgcc-s1 package name change.

 -- Matthias Klose <email address hidden>  Sun, 22 Mar 2020 16:52:38 +0100
Obsolete in disco-updates
Obsolete in disco-security
openexr (2.2.1-4.1ubuntu0.1) disco-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2017-911x-2.patch: address pointer overflows in
      IlmImf/ImfScanLineInputFile.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp.
    - debian/patches/CVE-2017-911x-3.patch: merge common fixes and move
      bounds check to central location in IlmImf/ImfFrameBuffer.h,
      IlmImf/ImfHeader.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp, exrmaketiled/Image.h,
      exrmultiview/Image.h.
    - debian/patches/CVE-2017-911x-4.patch: refactor origin function to a
      Slice factory and Rgba custom utility in IlmImf/ImfFrameBuffer.cpp,
      IlmImf/ImfFrameBuffer.h, IlmImf/ImfRgbaFile.h,
      exrenvmap/readInputImage.cpp, exrmakepreview/makePreview.cpp,
      exrmaketiled/Image.h, exrmultiview/Image.h.
    - CVE-2017-9111
    - CVE-2017-9113
    - CVE-2017-9115
    - CVE-2018-18444

 -- Marc Deslauriers <email address hidden>  Wed, 02 Oct 2019 13:01:44 -0400
Superseded in bionic-updates
Superseded in bionic-security
openexr (2.2.0-11.1ubuntu1.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2017-911x-2.patch: address pointer overflows in
      IlmImf/ImfScanLineInputFile.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp.
    - debian/patches/CVE-2017-911x-3.patch: merge common fixes and move
      bounds check to central location in IlmImf/ImfFrameBuffer.h,
      IlmImf/ImfHeader.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp, exrmaketiled/Image.h,
      exrmultiview/Image.h.
    - debian/patches/CVE-2017-911x-4.patch: refactor origin function to a
      Slice factory and Rgba custom utility in IlmImf/ImfFrameBuffer.cpp,
      IlmImf/ImfFrameBuffer.h, IlmImf/ImfRgbaFile.h,
      exrenvmap/readInputImage.cpp, exrmakepreview/makePreview.cpp,
      exrmaketiled/Image.h, exrmultiview/Image.h.
    - CVE-2017-9111
    - CVE-2017-9113
    - CVE-2017-9115
    - CVE-2018-18444

 -- Marc Deslauriers <email address hidden>  Wed, 02 Oct 2019 13:50:41 -0400
Superseded in xenial-updates
Superseded in xenial-security
openexr (2.2.0-10ubuntu2.1) xenial-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2017-911x.patch: add additional input validation
      in IlmImf/ImfDwaCompressor.cpp, IlmImf/ImfHuf.cpp,
      IlmImf/ImfPizCompressor.cpp.
    - debian/patches/CVE-2017-911x-2.patch: address pointer overflows in
      IlmImf/ImfScanLineInputFile.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp.
    - debian/patches/CVE-2017-911x-3.patch: merge common fixes and move
      bounds check to central location in IlmImf/ImfFrameBuffer.h,
      IlmImf/ImfHeader.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp, exrmaketiled/Image.h,
      exrmultiview/Image.h.
    - debian/patches/CVE-2017-911x-4.patch: refactor origin function to a
      Slice factory and Rgba custom utility in IlmImf/ImfFrameBuffer.cpp,
      IlmImf/ImfFrameBuffer.h, IlmImf/ImfRgbaFile.h,
      exrenvmap/readInputImage.cpp, exrmakepreview/makePreview.cpp,
      exrmaketiled/Image.h, exrmultiview/Image.h.
    - CVE-2017-9110
    - CVE-2017-9111
    - CVE-2017-9112
    - CVE-2017-9113
    - CVE-2017-9115
    - CVE-2017-9116
    - CVE-2017-12596
    - CVE-2018-18444

 -- Marc Deslauriers <email address hidden>  Wed, 02 Oct 2019 13:52:52 -0400
Superseded in focal-release
Superseded in focal-release
Obsolete in eoan-release
Deleted in eoan-proposed (Reason: moved to Release)
openexr (2.2.1-4.1ubuntu1) eoan; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/CVE-2017-911x-2.patch: address pointer overflows in
      IlmImf/ImfScanLineInputFile.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp.
    - debian/patches/CVE-2017-911x-3.patch: merge common fixes and move
      bounds check to central location in IlmImf/ImfFrameBuffer.h,
      IlmImf/ImfHeader.cpp, exrenvmap/readInputImage.cpp,
      exrmakepreview/makePreview.cpp, exrmaketiled/Image.h,
      exrmultiview/Image.h.
    - debian/patches/CVE-2017-911x-4.patch: refactor origin function to a
      Slice factory and Rgba custom utility in IlmImf/ImfFrameBuffer.cpp,
      IlmImf/ImfFrameBuffer.h, IlmImf/ImfRgbaFile.h,
      exrenvmap/readInputImage.cpp, exrmakepreview/makePreview.cpp,
      exrmaketiled/Image.h, exrmultiview/Image.h.
    - CVE-2017-9111
    - CVE-2017-9113
    - CVE-2017-9115
    - CVE-2018-18444

 -- Marc Deslauriers <email address hidden>  Wed, 02 Oct 2019 13:01:44 -0400
Superseded in focal-release
Deleted in focal-proposed (Reason: moved to Release)
openexr (2.3.0-6) unstable; urgency=medium

  * Upload to unstable (Closes: #919036)
  * debian/: debhelper bump 11 -> 12
  * debian/control: S-V bump 4.3.0 -> 4.4.0 (no changes needed)

 -- Matteo F. Vescovi <email address hidden>  Mon, 02 Sep 2019 16:23:00 +0200
Superseded in eoan-release
Obsolete in disco-release
Deleted in disco-proposed (Reason: moved to release)
openexr (2.2.1-4.1) unstable; urgency=medium

  * Non-maintainer upload.
  * bug909865.patch: Add -ffloat-store when compiling tests, to fix test
    failures on i386. Patch backported from experimental. (Closes: #909865)

 -- Steinar H. Gunderson <email address hidden>  Wed, 20 Mar 2019 22:40:43 +0100
Superseded in disco-release
Obsolete in cosmic-release
Deleted in cosmic-proposed (Reason: moved to release)
openexr (2.2.1-4build1) cosmic; urgency=medium

  * No-change rebuild against latest ilmbase

 -- Rik Mills <email address hidden>  Thu, 24 May 2018 16:03:33 +0100
Superseded in cosmic-proposed
openexr (2.2.1-4) unstable; urgency=medium

  * Upload to unstable

 -- Matteo F. Vescovi <email address hidden>  Sun, 11 Mar 2018 14:10:23 +0100
Superseded in cosmic-release
Published in bionic-release
Deleted in bionic-proposed (Reason: moved to release)
openexr (2.2.0-11.1ubuntu1) bionic; urgency=medium

  * Merge with Debian unstable (LP: #1742243). Remaining changes:
    - Add ppc64el to the archs where to ignore test results.

Superseded in bionic-release
Obsolete in artful-release
Obsolete in zesty-release
Obsolete in yakkety-release
Deleted in yakkety-proposed (Reason: moved to release)
openexr (2.2.0-11ubuntu1) yakkety; urgency=medium

  * Merge with Debian unstable (LP: #1628583). Remaining changes:
    - Add ppc64el to the archs where to ignore test results.
  * Drop:
    - Mark as optional symbols that aren't exported when building with
      -O3.
      [ symbols filed dropped in 2.2.0-11 ]

 -- Nishanth Aravamudan <email address hidden>  Wed, 28 Sep 2016 09:06:18 -0700
Superseded in yakkety-release
Published in xenial-release
Deleted in xenial-proposed (Reason: moved to release)
openexr (2.2.0-10ubuntu2) xenial; urgency=medium

  * Add ppc64el to the archs where to ignore test results.

 -- Matthias Klose <email address hidden>  Sun, 17 Apr 2016 20:13:32 +0200
Superseded in xenial-proposed
openexr (2.2.0-10ubuntu1) xenial; urgency=medium

  * Merge with Debian; remaining changes:

Superseded in xenial-release
Deleted in xenial-proposed (Reason: moved to release)
openexr (2.2.0-9ubuntu1) xenial; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - Mark as optional symbols that aren't exported when building with -O3.

Available diffs

Superseded in xenial-release
Deleted in xenial-proposed (Reason: moved to release)
openexr (2.2.0-7ubuntu1) xenial; urgency=medium

  * Mark as optional symbols that aren't exported when building with -O3.

 -- Steve Langasek <email address hidden>  Sat, 05 Dec 2015 00:12:51 +0000
Superseded in xenial-proposed
openexr (2.2.0-7) experimental; urgency=medium

  * Fix symbols on armel/powerpc/armhf

 -- Mathieu Malaterre <email address hidden>  Mon, 19 Oct 2015 14:47:28 +0200
Superseded in xenial-release
Obsolete in wily-release
Deleted in wily-proposed (Reason: moved to release)
openexr (2.2.0-1ubuntu3) wily; urgency=medium

  * Fix tests on big endian targets (taken from Fedora).
  * Ignore test results on 32bit archs.

 -- Matthias Klose <email address hidden>  Thu, 06 Aug 2015 00:23:37 +0200
Superseded in wily-proposed
openexr (2.2.0-1ubuntu2) wily; urgency=medium

  * Re-enable dh-autoreconf (don't run autoheader).
  * Disable the symbols file for now. New soname, and needs updates
    for the new libstdc++6 ABI.

Available diffs

Superseded in wily-proposed
openexr (2.2.0-1ubuntu1) wily; urgency=medium

  * Re-enable dh-autoreconf.
  * Disable the symbols file for now. New soname, and needs updates
    for the new libstdc++6 ABI.

Superseded in wily-release
Obsolete in vivid-release
Deleted in vivid-proposed (Reason: moved to release)
openexr (1.6.1-8) unstable; urgency=medium


  * QA upload.
  * Orphan package, set maintainer to QA.
  * Add 20_autoreconf.diff by Andreas Barth to let autoreconf run successfully
    and use dh-autoreconf. Closes: #759719
  * Point Vcs-* to anonscm.debian.org.

 -- Andreas Metzler <email address hidden>  Sun, 31 Aug 2014 07:56:20 +0200
150 of 72 results