USN-831-1 -- openexr vulnerabilitiesID: oval:org.secpod.oval:def:700446 | Date: (C)2011-05-13 (M)2024-02-15 |
Class: PATCH | Family: unix |
Drew Yao discovered several flaws in the way OpenEXR handled certain malformed EXR image files. If a user were tricked into opening a crafted EXR image file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. It was discovered that OpenEXR did not properly handle certain malformed EXR image files. If a user were tricked into opening a crafted EXR image file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. This issue only affected Ubuntu 8.04 LTS
Platform: |
Ubuntu 8.10 |
Ubuntu 8.04 |
Ubuntu 9.04 |