In 3.1.9 (https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.1.9): OSS-fuzz [59382](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=59382) Heap-buffer-overflow in internal_huf_decompress In 3.1.10 (https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.1.10): OSS-fuzz [59457](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=59457) Heap-buffer-overflow in ``LossyDctDecoder_execute`` In 3.2.0 (https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.0): * OSS-fuzz [46459](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46459) Out-of-memory in ``openexr_exrcheck_fuzzer`` * OSS-fuzz [46432](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46432) Heap-buffer-overflow in ``generic_unpack`` * OSS-fuzz [46413](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46413) Integer-overflow in ``reconstruct_chunk_table`` * OSS-fuzz [45718](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=45718) Heap-double-free in ``Imf_3_1::RgbaInputFile::~RgbaInputFile`` * OSS-fuzz [45716](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=45716) Abrt in ``Imf_3_1::RgbaInputFile::~RgbaInputFile`` * OSS-fuzz [43771](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=43771) Direct-leak in ``Imf_3_1::RgbaInputFile::RgbaInputFile`` Please bump to >=3.2.0.
CVE-2023-5841 (https://takeonme.org/cves/CVE-2023-5841.html): Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. Fixed in 3.1.12 and 3.2.2 according to their release notes: https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.1.12 https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.2
The bug has been closed via the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b98534f3604d967cd45877e8c1752cd7116563ca commit b98534f3604d967cd45877e8c1752cd7116563ca Author: Paul Zander <negril.nx+gentoo@gmail.com> AuthorDate: 2023-10-26 08:07:14 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2024-02-21 01:44:49 +0000 media-libs/openexr: add 3.1.12, 3.2.2 Closes: https://bugs.gentoo.org/920528 Closes: https://bugs.gentoo.org/916514 Closes: https://bugs.gentoo.org/908257 Signed-off-by: Paul Zander <negril.nx+gentoo@gmail.com> Closes: https://github.com/gentoo/gentoo/pull/34218 Signed-off-by: Sam James <sam@gentoo.org> media-libs/openexr/Manifest | 3 + .../files/openexr-3.2.1-bintests-iff-utils.patch | 14 +++ media-libs/openexr/openexr-3.1.12.ebuild | 69 +++++++++++ media-libs/openexr/openexr-3.2.2.ebuild | 130 +++++++++++++++++++++ 4 files changed, 216 insertions(+)
See the "Note:" at the top of security bugs.
Thanks, please stable when ready.