Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 908257

Summary: <media-libs/openexr-3.1.11: oss-fuzz stack buffer overread
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: minor CC: ajak, media-video, proxy-maint, waebbl-gentoo
Priority: Normal Keywords: PullRequest
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.1.8
See Also: https://github.com/gentoo/gentoo/pull/34218
Whiteboard: B4 [stable]
Package list:
Runtime testing required: ---
Bug Depends on: 920470    
Bug Blocks:    

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-06-10 18:46:37 UTC
"This release also addresses:

    OSS-fuzz 59070 Stack-buffer-overflow in DwaCompressor_readChannelRules"

Fix is in 3.1.8, please bump.
Comment 1 Larry the Git Cow gentoo-dev 2024-02-21 01:45:25 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b98534f3604d967cd45877e8c1752cd7116563ca

commit b98534f3604d967cd45877e8c1752cd7116563ca
Author:     Paul Zander <negril.nx+gentoo@gmail.com>
AuthorDate: 2023-10-26 08:07:14 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2024-02-21 01:44:49 +0000

    media-libs/openexr: add 3.1.12, 3.2.2
    
    Closes: https://bugs.gentoo.org/920528
    Closes: https://bugs.gentoo.org/916514
    Closes: https://bugs.gentoo.org/908257
    Signed-off-by: Paul Zander <negril.nx+gentoo@gmail.com>
    Closes: https://github.com/gentoo/gentoo/pull/34218
    Signed-off-by: Sam James <sam@gentoo.org>

 media-libs/openexr/Manifest                        |   3 +
 .../files/openexr-3.2.1-bintests-iff-utils.patch   |  14 +++
 media-libs/openexr/openexr-3.1.12.ebuild           |  69 +++++++++++
 media-libs/openexr/openexr-3.2.2.ebuild            | 130 +++++++++++++++++++++
 4 files changed, 216 insertions(+)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2024-02-21 02:17:23 UTC
See the "Note:" at the top of sec bugs.