drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in OpenEXR
Name: |
Ausführen beliebiger Kommandos in OpenEXR |
|
ID: |
USN-5144-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 18.04 LTS, Ubuntu 16.04 ESM |
|
Datum: |
Do, 11. November 2021, 18:50 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3933 |
|
Applikationen: |
OpenEXR |
|
Originalnachricht |
--===============4493633322736948427== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="OXfL5xGRrasGEqWY" Content-Disposition: inline
--OXfL5xGRrasGEqWY Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-5144-1 November 11, 2021
openexr vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS - Ubuntu 16.04 ESM
Summary:
OpenEXR could be made to crash or execute arbitrary code if it received a specially crafted EXR file.
Software Description: - openexr: tools for the OpenEXR image format
Details:
It was discovered that OpenEXR incorrectly handled certain EXR image files. An attacker could possibly use this issue to cause a crash or execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04 LTS: libopenexr22 2.2.0-11.1ubuntu1.8 openexr 2.2.0-11.1ubuntu1.8
Ubuntu 16.04 ESM: libopenexr22 2.2.0-10ubuntu2.6+esm2 openexr 2.2.0-10ubuntu2.6+esm2
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-5144-1 CVE-2021-3933
Package Information: https://launchpad.net/ubuntu/+source/openexr/2.2.0-11.1ubuntu1.8
--OXfL5xGRrasGEqWY Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAmGNU30ACgkQRbznW4QL H2kqBQ//ejXi9VW6/1HvuwKkE1N8Mw5RNGu/Hs5wS36uoDkFyqRBgN1vTp1z8e9v mKmkcuVijBxdKpTpxc20wgVWgV2pcbVFu9z3xSwUljyJpl8uEwTL8WYmwoG1bfVX efN92/qfpWurKcmms9JRGjD2CQt58OCe54mQBlhkug66FIQBEteyHkeRrXybWHzq ZRQuz8jC7S1ntSIulzb/gOKECIXBZMG18GZ91b4ctkgbcvL5UOeMjtUk1Ug0MIoB aTwhIXCtqOfrGOh4lznzS1eNG+fjAN/+yr2R66NrUxTbX8CsjW20yUAQ0EaKXQbL HhAsiuyuuYgIY/vGl0Qj0mdDspCGcR2/BIv2CmeS2A8KsN8xy4/vWljJAnQNt3VA 5egWqUPNWejAHUCkcuAHsjlUbwjLGEgtv/Cfhw8bWH0SBGR8v+n81EkO+v/tV4ag ZUehzC1Zt0zoFIozvasXe+bN8cHSrPc/QlCrP5vljgdbce2UEGwSe4xAnzDr+2HF rqKHCIYKuj53UHncm8xZXHDlhTz/9rfZkZeTAua0FYxRk1vxbX3FSUM7cK3TNda0 ASvuCoABJbpFuBjIMSYgu7b/P/4Mumd1uwSPZ5qnbww1VCYBeDWSqhazxe1NVeRo nwp9/aIhYaJhj4dP38gGrdtoiyAvor+maGMuNipbb4Rmr7PHX3w= =XBz2 -----END PGP SIGNATURE-----
--OXfL5xGRrasGEqWY--
--===============4493633322736948427== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
|
|
|
|