[Bug 297486] graphics/openexr: update to 3.4.14 to fix security vulnerabilities

[email protected]
Newsgroups gmane.os.freebsd.devel.ports.bugs
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297486

--- Comment #6 from [email protected] ---
A commit in branch 2026Q3 references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=d03d45178f4b716d7e34b1e024b51f83fb8325ac

commit d03d45178f4b716d7e34b1e024b51f83fb8325ac
Author:     Matthias Andree <[email protected]>
AuthorDate: 2026-08-12 21:00:34 +0000
Commit:     Yusuf Yaman <[email protected]>
CommitDate: 2026-08-14 10:01:18 +0000

    graphics/openexr*: Security update 3.4.13 => 3.4.14

    Changelog:
    https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.14

    PR:             297486
    Reported by:    mandree (maintainer)
    Approved by:    osa, vvd (Mentors, implicit)
    Pull Request:   https://github.com/freebsd/freebsd-ports/pull/580
    MFH:            2026Q3
    Security:       CVE-2026-68514 PyOpenEXR deep prefixed literal RGB key
collision heap buffer overflow
    Security:       CVE-2026-68513 PyOpenEXR prefixed literal RGB key collision
heap buffer overflow
    Security:       CVE-2026-62986 PyOpenEXR deep prefixed RGB stale lane
disclosure
    Security:       CVE-2026-61703 PyOpenEXR deep mixed RGB heap buffer
overflow
    Security:       CVE-2026-61555 empty multiView viewFromChannelName file
crash
    Security:       CVE-2026-59985 ILP32 OpenEXRCore RLE decode heap OOB read
DoS
    Security:       CVE-2026-59984 ILP32 B44 InputFile decode scratch buffer
overflow
    Security:       CVE-2026-59983 ILP32 DeepTiledInputFile sample count table
decode OOB read
    Security:       CVE-2026-59982 ILP32 DWAA InputFile packed AC buffer
overflow
    Security:       CVE-2026-59981 OpenEXRUtil SampleCountChannel row nonzero
dataWindow heap OOB read
    Security:       CVE-2026-59189 OpenEXRUtil DeepImageChannel row nonzero
dataWindow heap OOB read
    Security:       CVE-2026-59187 OpenEXR exrmetrics deep pixelmode heap
buffer overflow
    Security:       CVE-2026-59186 OpenEXR ILP32 TiledRgbaInputFile large tile
Array2D heap OOB write
    Security:       CVE-2026-59184 OpenEXRUtil FlatImageChannel row nonzero
dataWindow heap OOB write
    Security:       CVE-2026-59183 Signed Integer Overflow Leading to
Out-of-Bounds Memory Access in Deep Tile Decoding

    (cherry picked from commit 43e43009bbb057f5dbcd4351a7172e6fe4a2d7c1)

 graphics/openexr-website-docs/Makefile | 4 ++--
 graphics/openexr-website-docs/distinfo | 6 +++---
 graphics/openexr/Makefile              | 4 ++--
 graphics/openexr/distinfo              | 6 +++---
 4 files changed, 10 insertions(+), 10 deletions(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.