PublicDateAtUSN: 2017-05-21 18:29:00 UTC Candidate: CVE-2017-9111 PublicDate: 2017-05-21 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9111 http://www.openwall.com/lists/oss-security/2017/05/12/5 https://ubuntu.com/security/notices/USN-4148-1 https://ubuntu.com/security/notices/USN-4339-1 Description: In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code. Ubuntu-Description: Notes: mdeslaur> see suse bug for reproducer with exrmakepreview mdeslaur> first patch in upstream bug doesn't cover this CVE mdeslaur> mdeslaur> The patch for this issue was dropped during the focal mdeslaur> development cycle by mistake. Bugs: https://github.com/openexr/openexr/issues/232 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864078 https://bugzilla.suse.com/show_bug.cgi?id=1040109 Priority: low Discovered-by: Brandon Perry Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_openexr: upstream: https://github.com/openexr/openexr/commit/4aa6a4e0fcd52b220c71807307b9139966c3644c (2.4) upstream: https://github.com/openexr/openexr/commit/6a41400b47d574a5fc6133b9a7139bcd7b59d585 (2.4) upstream: https://github.com/openexr/openexr/commit/119eb2d4672e5c77a79929758f7e4c566f47c794 (2.4) upstream: https://github.com/openexr/openexr/commit/45f9912e6cfa0617ec2054d96d1e1e73fad4a62a (2.3) upstream: https://github.com/openexr/openexr/commit/a7eec54765e9122b78a6c34bb9d5bf744631bea2 (2.3) upstream: https://github.com/openexr/openexr/commit/ec64836c2312b13034149acab499c112bd289cd9 (2.3) upstream_openexr: needs-triage precise/esm_openexr: DNE trusty_openexr: ignored (reached end-of-life) trusty/esm_openexr: DNE (trusty was deferred [2019-05-27]) vivid/ubuntu-core_openexr: DNE xenial_openexr: released (2.2.0-10ubuntu2.1) esm-infra/xenial_openexr: released (2.2.0-10ubuntu2.1) zesty_openexr: ignored (reached end-of-life) artful_openexr: ignored (reached end-of-life) bionic_openexr: released (2.2.0-11.1ubuntu1.1) cosmic_openexr: ignored (reached end-of-life) disco_openexr: released (2.2.1-4.1ubuntu0.1) eoan_openexr: released (2.2.1-4.1ubuntu0.1) focal_openexr: released (2.3.0-6ubuntu0.1) devel_openexr: released (2.3.0-6ubuntu0.1)