<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en">
<head>
<meta content="text/html; charset=US-ASCII" http-equiv="Content-Type">
<title>
GitLab
</title>
<style>img {
max-width: 100%; height: auto;
}
</style>
</head>
<body>
<div class="content">
<h3>
Sylvain Beucler pushed to branch master
at <a href="https://salsa.debian.org/security-tracker-team/security-tracker">Debian Security Tracker / security-tracker</a>
</h3>
<h4>
Commits:
</h4>
<ul>
<li>
<strong><a href="https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbe3854d4737b1de1924ffd3148eb59b51088c40">fbe3854d</a></strong>
<div>
<span>by Sylvain Beucler</span>
<i>at 2021-07-03T15:49:33+02:00</i>
</div>
<pre class="commit-message" style="white-space: pre-wrap; margin: 0;">CVE-2021-23215/openexr: clarify patches some more
(Following prompt by carnil)
de27156 is a pre-requisite for the 2.x branches (especially our 2.2.x versions).
Without it (especially chunk #4 whose code range is untouched by the other patch) the test suite fails.
$ ./IlmImfTest testCompression
tempDir = /var/tmp/IlmImfTest_ODOFNYZG
=======
Running testCompression
Testing pixel data types, subsampling and compression schemes
only zeroes
compression 0, x sampling 1, y sampling 1: writing reading comparing
compression 1, x sampling 1, y sampling 1: writing reading comparing
compression 2, x sampling 1, y sampling 1: writing reading comparing
compression 3, x sampling 1, y sampling 1: writing reading comparing
compression 4, x sampling 1, y sampling 1: writing readingImfFastHuf.cpp:392:48: runtime error: shift exponent 64 is too large for 64-bit type 'long unsigned int'
comparing
compression 5, x sampling 1, y sampling 1: writing reading comparing
compression 6, x sampling 1, y sampling 1: writing reading../IlmImf/ImfXdr.h:679:9: runtime error: left shift of negative value -15
comparing
compression 7, x sampling 1, y sampling 1: writing reading comparing
compression 8, x sampling 1, y sampling 1: writing readingERROR -- caught exception: Error reading pixel data from image file "/var/tmp/IlmImfTest_ODOFNYZG/imf_test_comp.exr". Error uncompressing DWA data(corrupt header).
IlmImfTest: testCompression.cpp:433: void testCompression(const string&): Assertion `false' failed.
Abandon
</pre>
</li>
</ul>
<h4>1 changed file:</h4>
<ul>
<li class="file-stats">
<a href="#4716ef5aa8f2742228ba3b3633215c8b808565e3">
data/CVE/list
</a>
</li>
</ul>
<h4>Changes:</h4>
<li id="4716ef5aa8f2742228ba3b3633215c8b808565e3">
<a href="https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbe3854d4737b1de1924ffd3148eb59b51088c40#4716ef5aa8f2742228ba3b3633215c8b808565e3"><strong>data/CVE/list</strong></a>
<hr>
No preview for this file type
<br>
</li>
</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #666;">
—
<br>
<a href="https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbe3854d4737b1de1924ffd3148eb59b51088c40">View it on GitLab</a>.
<br>
You're receiving this email because of your account on salsa.debian.org.
If you'd like to receive fewer emails, you can
adjust your notification settings.
<script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","action":{"@type":"ViewAction","name":"View Commit","url":"https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbe3854d4737b1de1924ffd3148eb59b51088c40"}}</script>
</p>
</div>
</body>
</html>