[Git][security-tracker-team/security-tracker][master] Add three new openexr issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jun 6 20:23:23 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac2f871d by Salvatore Bonaccorso at 2021-06-06T21:22:51+02:00
Add three new openexr issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5552,10 +5552,26 @@ CVE-2021-31525 (net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows re
 	TODO: check details for golang-1.11 and older
 CVE-2021-26945
 	RESERVED
+	- openexr <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1947591
+	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31221
+	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31228
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/930
+	TODO: check details
 CVE-2021-26260
 	RESERVED
+	- openexr <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1947582
+	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29423
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/894
+	TODO: check details
 CVE-2021-23215
 	RESERVED
+	- openexr <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1947586
+	NOTE: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29653
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/901
+	TODO: check details
 CVE-2021-23169 [Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer]
 	RESERVED
 	- openexr 2.5.4-2 (bug #988240)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac2f871d83accbfbc56e1402f41ef4f3f21fe626

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac2f871d83accbfbc56e1402f41ef4f3f21fe626
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210606/13136859/attachment.htm>


More information about the debian-security-tracker-commits mailing list