FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

nothing found there

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
b1d6b383-dd51-11ea-a688-7b12871ef3adilmbase, openexr -- v2.5.3 is a patch release with various bug/security fixes

Cary Phillips reports:

v2.5.3 - Patch release with various bug/security fixes [...]:

  • Various sanitizer/fuzz-identified issues related to handling of invalid input

Discovery 2020-07-13
Entry 2020-08-13
ilmbase
lt 2.5.3

openexr
lt 2.5.3

https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.3
714e6c35-c75b-11ea-aa29-d74973d1f9f3OpenEXR/ilmbase 2.5.2 -- patch release with various bug/security fixes

Cary Phillips reports:

openexr 2.5.2 [is a p]atch release with various bug/security and build/install fixes:

  • Invalid input could cause a heap-use-after-free error in DeepScanLineInputFile::DeepScanLineInputFile()
  • Invalid chunkCount attributes could cause heap buffer overflow in getChunkOffsetTableSize()
  • Invalid tiled input file could cause invalid memory access TiledInputFile::TiledInputFile()

Discovery 2020-05-18
Entry 2020-07-16
ilmbase
lt 2.5.2

openexr
lt 2.5.2

https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.2
98044aba-6d72-11eb-aed7-1b1b8a70cc8bopenexr, ilmbase -- security fixes related to reading corrupted input files

Cary Phillips reports:

Patch release with various bug/sanitizer/security fixes, primarily related to reading corrupted input files[...].


Discovery 2021-02-12
Entry 2021-02-12
ilmbase
lt 2.5.5

openexr
lt 2.5.5

https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.5
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.5.4
CVE-2021-20296
CVE-2021-3479
CVE-2021-3478
CVE-2021-3477
CVE-2021-3476
CVE-2021-3475
CVE-2021-3474