Bug ID 1205021
Summary VUL-0: CVE-2022-41838: OpenImageIO: crash when processing cubemap files and a cube face was not present
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/347024/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee hpj@urpla.net
Reporter carlos.lopez@suse.com
QA Contact security-team@suse.de
CC adrian.schroeter@suse.com
Found By Security Response Team
Blocker ---

rh#2139797

From https://github.com/OpenImageIO/oiio/releases/tag/v2.3.21.0:

RLA: fix potential buffer overrun. (TALOS-2022-1629, CVE-2022-36354) #3624
TIFF: guard against corrupt files with buffer overflows. (TALOS-2022-1627,
CVE-2022-41977) #3628
TIFF: guard against buffer overflow for certain CMYK files.
(TALOS-2022-1633, CVE-2022-41639) (TALOS-2022-1643, CVE-2022-41988) #3632

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2139797
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41838


You are receiving this mail because: