|
Number of commits found: 2
| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| This is a slave port. You may also want to view the commits to the master port: graphics/openexr | | Commit | Credits | Log message |
3.4.15 22 Aug 2026 08:41:50
    |
Gleb Popov (arrowd)  Author: Matthias Andree |
graphics/openexr*: security fix update to v3.4.15
"v3.4.15 fixes two memory issues when parsing IDManifests. Corrupt
or maliciously formed OpenEXR images could trigger excessive memory
allocation, but only in code which decodes the idmanifest attribute.
Other code is unaffected, even when handling files with idmanifest
attributes [...] CVEs have been requested for these issues."
<https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.15>
CVEs are not yet communicated.
Changelog: https://github.com/AcademySoftwareFoundation/openexr/blob/v3.4.15/CHANGES.md#version-3415-august-21-2026
Pull request: https://github.com/freebsd/freebsd-ports/pull/594
MFH: 2026Q3
PR: 297717
(cherry picked from commit e51c07e1f89545680baab090f517391137ca5834) |
3.4.14 14 Aug 2026 10:01:18
    |
Yusuf Yaman (nxjoseph)  Author: Matthias Andree |
graphics/openexr*: Security update 3.4.13 => 3.4.14
Changelog:
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.14
PR: 297486
Reported by: mandree (maintainer)
Approved by: osa, vvd (Mentors, implicit)
Pull Request: https://github.com/freebsd/freebsd-ports/pull/580
MFH: 2026Q3
Security: CVE-2026-68514 PyOpenEXR deep prefixed literal RGB key collision heap
buffer overflow
Security: CVE-2026-68513 PyOpenEXR prefixed literal RGB key collision heap
buffer overflow
Security: CVE-2026-62986 PyOpenEXR deep prefixed RGB stale lane disclosure
Security: CVE-2026-61703 PyOpenEXR deep mixed RGB heap buffer overflow
Security: CVE-2026-61555 empty multiView viewFromChannelName file crash (Only the first 15 lines of the commit message are shown above ) |
Number of commits found: 2
|