File _patchinfo of Package patchinfo.20698
<patchinfo incident="20698">
<issue tracker="cve" id="2021-20304"/>
<issue tracker="cve" id="2021-3476"/>
<issue tracker="cve" id="2021-20300"/>
<issue tracker="cve" id="2021-20298"/>
<issue tracker="cve" id="2021-20299"/>
<issue tracker="cve" id="2021-20303"/>
<issue tracker="cve" id="2021-20302"/>
<issue tracker="bnc" id="1188459">VUL-0: CVE-2021-20299: openexr: Null-dereference READ in Imf_2_5:Header:operator</issue>
<issue tracker="bnc" id="1188458">VUL-0: CVE-2021-20300: OpenEXR,openexr: Integer-overflow in Imf_2_5:hufUncompress</issue>
<issue tracker="bnc" id="1188462">VUL-0: CVE-2021-20302: openexr: Floating-point-exception in Imf_2_5:precalculateTileInfot</issue>
<issue tracker="bnc" id="1188457">VUL-0: CVE-2021-20303: openexr,OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer</issue>
<issue tracker="bnc" id="1188461">VUL-0: CVE-2021-20304: OpenEXR,openexr: OpenEXR: Undefined-shift in Imf_2_5:hufDecode</issue>
<issue tracker="bnc" id="1188460">VUL-0: CVE-2021-20298: openexr,OpenEXR: Out-of-memory in B44Compressor</issue>
<packager>pgajdos</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for openexr</summary>
<description>This update for openexr fixes the following issues:
- CVE-2021-20298 [bsc#1188460]: Fixed Out-of-memory in B44Compressor
- CVE-2021-20299 [bsc#1188459]: Fixed Null-dereference READ in Imf_2_5:Header:operator
- CVE-2021-20300 [bsc#1188458]: Fixed Integer-overflow in Imf_2_5:hufUncompress
- CVE-2021-20302 [bsc#1188462]: Fixed Floating-point-exception in Imf_2_5:precalculateTileInfot
- CVE-2021-20303 [bsc#1188457]: Fixed Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
- CVE-2021-20304 [bsc#1188461]: Fixed Undefined-shift in Imf_2_5:hufDecode
</description>
</patchinfo>