openexr: CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115

Debian Bug report logs - #873885
openexr: CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Sun, 4 Jun 2017 06:48:02 UTC

Severity: important

Tags: patch, security

Found in version openexr/2.2.0-11

Fixed in version 2.2.1-1

Done: "Matteo F. Vescovi" <mfv@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>:
Bug#864078; Package src:openexr. (Sun, 04 Jun 2017 06:48:04 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>. (Sun, 04 Jun 2017 06:48:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2017-9110 CVE-2017-9111 CVE-2017-9112 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9116 CVE-2017-9117
Date: Sun, 04 Jun 2017 08:44:38 +0200
Source: openexr
Severity: grave
Tags: security

Please see http://www.openwall.com/lists/oss-security/2017/05/12/5

These were reported upstream at https://github.com/openexr/openexr/issues/232

Upstream fixes are linked in the github bug.

Cheers,
        Moritz



Marked as found in versions openexr/2.2.0-11. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 04 Jun 2017 06:57:02 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>:
Bug#864078; Package src:openexr. (Sun, 04 Jun 2017 12:48:04 GMT) (full text, mbox, link).


Acknowledgement sent to Mathieu Malaterre <malat@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>. (Sun, 04 Jun 2017 12:48:04 GMT) (full text, mbox, link).


Message #12 received at 864078@bugs.debian.org (full text, mbox, reply):

From: Mathieu Malaterre <malat@debian.org>
To: 864078@bugs.debian.org
Subject: Re: Bug#864078: CVE-2017-9110 CVE-2017-9111 CVE-2017-9112 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9116 CVE-2017-9117
Date: Sun, 4 Jun 2017 14:44:09 +0200
Control: tags -1 patch

https://github.com/binarycrusader/openexr/commit/749193265ac99956f01a2dd9b20f124f2f7859d0.patch



Added tag(s) patch. Request was from Mathieu Malaterre <malat@debian.org> to 864078-submit@bugs.debian.org. (Sun, 04 Jun 2017 12:48:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>:
Bug#864078; Package src:openexr. (Thu, 31 Aug 2017 22:21:02 GMT) (full text, mbox, link).


Acknowledgement sent to Markus Koschany <apo@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>. (Thu, 31 Aug 2017 22:21:02 GMT) (full text, mbox, link).


Message #19 received at 864078@bugs.debian.org (full text, mbox, reply):

From: Markus Koschany <apo@debian.org>
To: 864078@bugs.debian.org
Cc: control@bugs.debian.org
Subject: Re: Bug#864078: CVE-2017-9110 CVE-2017-9111 CVE-2017-9112 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9116 CVE-2017-9117
Date: Fri, 1 Sep 2017 00:16:44 +0200
[Message part 1 (text/plain, inline)]
clone 864078 -1
severity -1 important
thanks

I have prepared a security update for openexr which I am going to upload
in due course. The upload will fix CVE-2017-9110, CVE-2017-9112 and
CVE-2017-9116. The other CVE are not considered being critical by
upstream. In fact it looks more like they are just normal bugs in the
exr2aces test program which is not built by default. I'm going to clone
this bug report because of the outstanding issues but will lower the
severity to important.

Regards,

Markus
[openexr.debdiff (text/plain, attachment)]
[signature.asc (application/pgp-signature, attachment)]

Bug 864078 cloned as bug 873885 Request was from Markus Koschany <apo@debian.org> to control@bugs.debian.org. (Thu, 31 Aug 2017 22:21:05 GMT) (full text, mbox, link).


Severity set to 'important' from 'grave' Request was from Markus Koschany <apo@debian.org> to control@bugs.debian.org. (Thu, 31 Aug 2017 22:21:06 GMT) (full text, mbox, link).


Changed Bug title to 'CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9117' from 'CVE-2017-9110 CVE-2017-9111 CVE-2017-9112 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9116 CVE-2017-9117'. Request was from Markus Koschany <apo@debian.org> to control@bugs.debian.org. (Thu, 31 Aug 2017 22:27:05 GMT) (full text, mbox, link).


Changed Bug title to 'openexr: CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115' from 'CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9117'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Fri, 01 Sep 2017 04:12:02 GMT) (full text, mbox, link).


Reply sent to "Matteo F. Vescovi" <mfv@debian.org>:
You have taken responsibility. (Wed, 10 Jan 2018 16:39:03 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Wed, 10 Jan 2018 16:39:03 GMT) (full text, mbox, link).


Message #32 received at 873885-done@bugs.debian.org (full text, mbox, reply):

From: "Matteo F. Vescovi" <mfv@debian.org>
To: Moritz Muehlenhoff <jmm@debian.org>
Cc: 873885-done@bugs.debian.org
Subject: Re: Bug#873885: CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115
Date: Wed, 10 Jan 2018 17:35:55 +0100
[Message part 1 (text/plain, inline)]
Version: 2.2.1-1

On 2017-06-04 at 09:44 (+0200), Moritz Muehlenhoff wrote:
> Source: openexr
> Severity: grave
> Tags: security
>
> Please see http://www.openwall.com/lists/oss-security/2017/05/12/5
>
> These were reported upstream at https://github.com/openexr/openexr/issues/232
>
> Upstream fixes are linked in the github bug.

OpenEXR 2.2.1-1 has been just uploaded to experimental with testing
purpose. Once reverse dependencies have been re-built against it, it
will be moved to unstable/sid.

Thus, this issue is now fixed. And closing.

Cheers.


-- 
Matteo F. Vescovi
[signature.asc (application/pgp-signature, inline)]

Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 08 Apr 2018 07:36:18 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:37:38 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.