[Git][security-tracker-team/security-tracker][master] CVE-2022-38143,openimageio: Bullseye is not affected.

Markus Koschany (@apo) apo at debian.org
Sun Apr 9 21:52:17 BST 2023



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d7dfcec by Markus Koschany at 2023-04-09T22:51:43+02:00
CVE-2022-38143,openimageio: Bullseye is not affected.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -45885,6 +45885,7 @@ CVE-2022-41639 (A heap based buffer overflow vulnerability exists in tile decodi
 	NOTE: https://github.com/OpenImageIO/oiio/pull/3632
 CVE-2022-38143 (A heap out-of-bounds write vulnerability exists in the way OpenImageIO ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
+	[bullseye] - openimageio <not-affected> (The vulnerable code was introduced later)
 	[buster] - openimageio <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1630
 	NOTE: https://github.com/OpenImageIO/oiio/pull/3620



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d7dfcecfd6cf1a1f7fb93dcaff9f34c9730afba

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d7dfcecfd6cf1a1f7fb93dcaff9f34c9730afba
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230409/4f317959/attachment.htm>


More information about the debian-security-tracker-commits mailing list