[Git][security-tracker-team/security-tracker][master] Add more openexr issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 05:43:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
de0ac70a by Salvatore Bonaccorso at 2026-08-26T06:42:45+02:00
Add more openexr issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -325,21 +325,44 @@ CVE-2026-59984 (OpenEXR is the reference implementation and specification for th
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/2a7386be8ec1b637dd7c6c3b91db47a6c472ed01 (v3.4.14-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/c550555a1657398e6a9f96c3530f8b1370a6fd94 (v3.2.11-rc)
CVE-2026-59983 (OpenEXR is the reference implementation and specification for the EXR ...)
- TODO: check
+ - openexr 3.4.14-0.1
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p42q-g5c9-mh9w
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/0efec58d2d28a0ee322f5028dee6fb57d459580e (v3.4.14-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/f0e404f7298cd8563a1d30a64a1c982dbd68fc49 (v3.3.13-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/78e91146fceeee317820a146ba99a96f380945b8 (v3.2.11-rc)
CVE-2026-59982 (OpenEXR is the reference implementation and specification for the EXR ...)
- TODO: check
+ - openexr 3.4.14-0.1
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6662-fq6f-93mp
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c (v3.4.14-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec (v3.3.13-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1 (v3.2.11-rc)
CVE-2026-59769 (FA-50 all versions contain hard-coded credentials. An attacker, who kn ...)
NOT-FOR-US: FA-50
CVE-2026-59335 (Improper handling of case sensitivity (CWE-178) in the identity zone a ...)
TODO: check
CVE-2026-59189 (OpenEXR is the reference implementation and specification for the EXR ...)
- TODO: check
+ - openexr 3.4.14-0.1
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c (v3.4.14-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec (v3.3.13-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1 (v3.2.11-rc)
CVE-2026-59187 (OpenEXR is the reference implementation and specification for the EXR ...)
- TODO: check
+ - openexr 3.4.14-0.1
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585 (v3.4.14-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94 (v3.3.13-rc)
CVE-2026-59186 (OpenEXR is the reference implementation and specification for the EXR ...)
- TODO: check
+ - openexr 3.4.14-0.1
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab (v3.4.14-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b (v3.3.13-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/904141d3a1f86327ad1e2b93fc92ce2dd5881d34 (v3.2.11-rc)
CVE-2026-59184 (OpenEXR is the reference implementation and specification for the EXR ...)
- TODO: check
+ - openexr 3.4.14-0.1
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pqp9-558c-453q
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c (v3.4.14-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec (v3.3.13-rc)
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1 (v3.2.11-rc)
CVE-2026-57910 (Improper authentication in the WatchGuard Agent allows an unauthentica ...)
NOT-FOR-US: WatchGuard
CVE-2026-57909 (A path traversal vulnerability in WatchGuard Agent allows a remote, un ...)
@@ -826,7 +849,9 @@ CVE-2026-68960 (A stack-based buffer overflow vulnerability exists in SKYSEA Cli
CVE-2026-68959 (SKYSEA Client View and SKYMEC IT Manager contain a path traversal vuln ...)
NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
CVE-2026-68516 (OpenEXR is the reference implementation and specification for the EXR ...)
- TODO: check
+ - openexr 3.4.14-0.1
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-fw66-6xph-56jm
+ NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/45521f92104373b5c850f27f2d4659ab6759e848 (v3.4.14-rc)
CVE-2026-68062 (SKYSEA Client View and SKYMEC IT Manager contain a path traversal vuln ...)
NOT-FOR-US: SKYSEA Client View and SKYMEC IT Manager
CVE-2026-66766 (SAP S/4HANA (Private Cloud) uses a third-party component that contains ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de0ac70a627b823121162059ce010802b526d96d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de0ac70a627b823121162059ce010802b526d96d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/8a48d1b6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list