Debian Bug report logs -
#873885
openexr: CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115
Reported by: Moritz Muehlenhoff <jmm@debian.org>
Date: Sun, 4 Jun 2017 06:48:02 UTC
Severity: important
Tags: patch, security
Found in version openexr/2.2.0-11
Fixed in version 2.2.1-1
Done: "Matteo F. Vescovi" <mfv@debian.org>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded
to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
:
Bug#864078
; Package src:openexr
.
(Sun, 04 Jun 2017 06:48:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Moritz Muehlenhoff <jmm@debian.org>
:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
.
(Sun, 04 Jun 2017 06:48:04 GMT) (full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Source: openexr
Severity: grave
Tags: security
Please see http://www.openwall.com/lists/oss-security/2017/05/12/5
These were reported upstream at https://github.com/openexr/openexr/issues/232
Upstream fixes are linked in the github bug.
Cheers,
Moritz
Marked as found in versions openexr/2.2.0-11.
Request was from Salvatore Bonaccorso <carnil@debian.org>
to control@bugs.debian.org
.
(Sun, 04 Jun 2017 06:57:02 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
:
Bug#864078
; Package src:openexr
.
(Sun, 04 Jun 2017 12:48:04 GMT) (full text, mbox, link).
Acknowledgement sent
to Mathieu Malaterre <malat@debian.org>
:
Extra info received and forwarded to list. Copy sent to Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
.
(Sun, 04 Jun 2017 12:48:04 GMT) (full text, mbox, link).
Message #12 received at 864078@bugs.debian.org (full text, mbox, reply):
Control: tags -1 patch
https://github.com/binarycrusader/openexr/commit/749193265ac99956f01a2dd9b20f124f2f7859d0.patch
Added tag(s) patch.
Request was from Mathieu Malaterre <malat@debian.org>
to 864078-submit@bugs.debian.org
.
(Sun, 04 Jun 2017 12:48:04 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
:
Bug#864078
; Package src:openexr
.
(Thu, 31 Aug 2017 22:21:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Markus Koschany <apo@debian.org>
:
Extra info received and forwarded to list. Copy sent to Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
.
(Thu, 31 Aug 2017 22:21:02 GMT) (full text, mbox, link).
Message #19 received at 864078@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
clone 864078 -1
severity -1 important
thanks
I have prepared a security update for openexr which I am going to upload
in due course. The upload will fix CVE-2017-9110, CVE-2017-9112 and
CVE-2017-9116. The other CVE are not considered being critical by
upstream. In fact it looks more like they are just normal bugs in the
exr2aces test program which is not built by default. I'm going to clone
this bug report because of the outstanding issues but will lower the
severity to important.
Regards,
Markus
[openexr.debdiff (text/plain, attachment)]
[signature.asc (application/pgp-signature, attachment)]
Bug 864078 cloned as bug 873885
Request was from Markus Koschany <apo@debian.org>
to control@bugs.debian.org
.
(Thu, 31 Aug 2017 22:21:05 GMT) (full text, mbox, link).
Severity set to 'important' from 'grave'
Request was from Markus Koschany <apo@debian.org>
to control@bugs.debian.org
.
(Thu, 31 Aug 2017 22:21:06 GMT) (full text, mbox, link).
Changed Bug title to 'CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9117' from 'CVE-2017-9110 CVE-2017-9111 CVE-2017-9112 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9116 CVE-2017-9117'.
Request was from Markus Koschany <apo@debian.org>
to control@bugs.debian.org
.
(Thu, 31 Aug 2017 22:27:05 GMT) (full text, mbox, link).
Changed Bug title to 'openexr: CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115' from 'CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9117'.
Request was from Salvatore Bonaccorso <carnil@debian.org>
to control@bugs.debian.org
.
(Fri, 01 Sep 2017 04:12:02 GMT) (full text, mbox, link).
Reply sent
to "Matteo F. Vescovi" <mfv@debian.org>
:
You have taken responsibility.
(Wed, 10 Jan 2018 16:39:03 GMT) (full text, mbox, link).
Notification sent
to Moritz Muehlenhoff <jmm@debian.org>
:
Bug acknowledged by developer.
(Wed, 10 Jan 2018 16:39:03 GMT) (full text, mbox, link).
Message #32 received at 873885-done@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Version: 2.2.1-1
On 2017-06-04 at 09:44 (+0200), Moritz Muehlenhoff wrote:
> Source: openexr
> Severity: grave
> Tags: security
>
> Please see http://www.openwall.com/lists/oss-security/2017/05/12/5
>
> These were reported upstream at https://github.com/openexr/openexr/issues/232
>
> Upstream fixes are linked in the github bug.
OpenEXR 2.2.1-1 has been just uploaded to experimental with testing
purpose. Once reverse dependencies have been re-built against it, it
will be moved to unstable/sid.
Thus, this issue is now fixed. And closing.
Cheers.
--
Matteo F. Vescovi
[signature.asc (application/pgp-signature, inline)]
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org
.
(Sun, 08 Apr 2018 07:36:18 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Wed Jun 19 14:37:38 2019;
Machine Name:
beach
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.