[Bug 297486] graphics/openexr: update to 3.4.14 to fix security vulnerabilities
| Newsgroups | gmane.os.freebsd.devel.ports.bugs |
|---|---|
| Message-ID | <[email protected]/bugzilla/> |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297486 --- Comment #6 from [email protected] --- A commit in branch 2026Q3 references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=d03d45178f4b716d7e34b1e024b51f83fb8325ac commit d03d45178f4b716d7e34b1e024b51f83fb8325ac Author: Matthias Andree <[email protected]> AuthorDate: 2026-08-12 21:00:34 +0000 Commit: Yusuf Yaman <[email protected]> CommitDate: 2026-08-14 10:01:18 +0000 graphics/openexr*: Security update 3.4.13 => 3.4.14 Changelog: https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.14 PR: 297486 Reported by: mandree (maintainer) Approved by: osa, vvd (Mentors, implicit) Pull Request: https://github.com/freebsd/freebsd-ports/pull/580 MFH: 2026Q3 Security: CVE-2026-68514 PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow Security: CVE-2026-68513 PyOpenEXR prefixed literal RGB key collision heap buffer overflow Security: CVE-2026-62986 PyOpenEXR deep prefixed RGB stale lane disclosure Security: CVE-2026-61703 PyOpenEXR deep mixed RGB heap buffer overflow Security: CVE-2026-61555 empty multiView viewFromChannelName file crash Security: CVE-2026-59985 ILP32 OpenEXRCore RLE decode heap OOB read DoS Security: CVE-2026-59984 ILP32 B44 InputFile decode scratch buffer overflow Security: CVE-2026-59983 ILP32 DeepTiledInputFile sample count table decode OOB read Security: CVE-2026-59982 ILP32 DWAA InputFile packed AC buffer overflow Security: CVE-2026-59981 OpenEXRUtil SampleCountChannel row nonzero dataWindow heap OOB read Security: CVE-2026-59189 OpenEXRUtil DeepImageChannel row nonzero dataWindow heap OOB read Security: CVE-2026-59187 OpenEXR exrmetrics deep pixelmode heap buffer overflow Security: CVE-2026-59186 OpenEXR ILP32 TiledRgbaInputFile large tile Array2D heap OOB write Security: CVE-2026-59184 OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write Security: CVE-2026-59183 Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding (cherry picked from commit 43e43009bbb057f5dbcd4351a7172e6fe4a2d7c1) graphics/openexr-website-docs/Makefile | 4 ++-- graphics/openexr-website-docs/distinfo | 6 +++--- graphics/openexr/Makefile | 4 ++-- graphics/openexr/distinfo | 6 +++--- 4 files changed, 10 insertions(+), 10 deletions(-) -- You are receiving this mail because: You are the assignee for the bug.