ALAS2-2020-1499

Related Vulnerabilities: CVE-2020-11761   CVE-2020-11763   CVE-2020-11764  

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp. (CVE-2020-11761) An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp. (CVE-2020-11763) An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. (CVE-2020-11764)

ALAS2-2020-1499


Amazon Linux 2 Security Advisory: ALAS-2020-1499
Advisory Release Date: 2020-10-22 17:15 Pacific
Advisory Updated Date: 2020-10-22 22:43 Pacific
Severity: Medium

Issue Overview:

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp. (CVE-2020-11761)

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp. (CVE-2020-11763)

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. (CVE-2020-11764)


Affected Packages:

OpenEXR


Issue Correction:
Run yum update OpenEXR to update your system.

New Packages:
aarch64:
    OpenEXR-1.7.1-8.amzn2.0.1.aarch64
    OpenEXR-devel-1.7.1-8.amzn2.0.1.aarch64
    OpenEXR-libs-1.7.1-8.amzn2.0.1.aarch64
    OpenEXR-debuginfo-1.7.1-8.amzn2.0.1.aarch64

i686:
    OpenEXR-1.7.1-8.amzn2.0.1.i686
    OpenEXR-devel-1.7.1-8.amzn2.0.1.i686
    OpenEXR-libs-1.7.1-8.amzn2.0.1.i686
    OpenEXR-debuginfo-1.7.1-8.amzn2.0.1.i686

src:
    OpenEXR-1.7.1-8.amzn2.0.1.src

x86_64:
    OpenEXR-1.7.1-8.amzn2.0.1.x86_64
    OpenEXR-devel-1.7.1-8.amzn2.0.1.x86_64
    OpenEXR-libs-1.7.1-8.amzn2.0.1.x86_64
    OpenEXR-debuginfo-1.7.1-8.amzn2.0.1.x86_64