FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-28 15:43:32 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
b1d6b383-dd51-11ea-a688-7b12871ef3adilmbase, openexr -- v2.5.3 is a patch release with various bug/security fixes

Cary Phillips reports:

v2.5.3 - Patch release with various bug/security fixes [...]:

  • Various sanitizer/fuzz-identified issues related to handling of invalid input

Discovery 2020-07-13
Entry 2020-08-13
ilmbase
< 2.5.3

openexr
< 2.5.3

https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.3
e4d9dffb-2a32-11ea-9693-e1b3f6feec79OpenEXR -- heap buffer overflow, and out-of-memory bugs

Cary Phillips reports:

OpenEXR (IlmBase) v2.4.0 fixes the following security vulnerabilities:

  • CVE-2018-18444 Issue #351 Out of Memory
  • CVE-2018-18443 Issue #350 heap-buffer-overflow

The relevant patches have been backported to the FreeBSD ports.


Discovery 2018-10-17
Entry 2019-12-29
ilmbase
< 2.3.0_4

openexr
< 2.3.0_3

https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.0
https://github.com/AcademySoftwareFoundation/openexr/issues/350
https://github.com/AcademySoftwareFoundation/openexr/issues/351
CVE-2018-18443
CVE-2018-18444
714e6c35-c75b-11ea-aa29-d74973d1f9f3OpenEXR/ilmbase 2.5.2 -- patch release with various bug/security fixes

Cary Phillips reports:

openexr 2.5.2 [is a p]atch release with various bug/security and build/install fixes:

  • Invalid input could cause a heap-use-after-free error in DeepScanLineInputFile::DeepScanLineInputFile()
  • Invalid chunkCount attributes could cause heap buffer overflow in getChunkOffsetTableSize()
  • Invalid tiled input file could cause invalid memory access TiledInputFile::TiledInputFile()

Discovery 2020-05-18
Entry 2020-07-16
ilmbase
< 2.5.2

openexr
< 2.5.2

https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.2
98044aba-6d72-11eb-aed7-1b1b8a70cc8bopenexr, ilmbase -- security fixes related to reading corrupted input files

Cary Phillips reports:

Patch release with various bug/sanitizer/security fixes, primarily related to reading corrupted input files[...].


Discovery 2021-02-12
Entry 2021-02-12
ilmbase
< 2.5.5

openexr
< 2.5.5

https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.5
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.4
CVE-2021-20296
CVE-2021-3479
CVE-2021-3478
CVE-2021-3477
CVE-2021-3476
CVE-2021-3475
CVE-2021-3474