Summary
The remote host is missing an update to openexr
announced via advisory DSA 1842-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201842-1
Insight
Several vulnerabilities have been discovered in the OpenEXR image library, which can lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2009-1720
Drew Yao discovered integer overflows in the preview and compression code.
CVE-2009-1721
Drew Yao discovered that an uninitialised pointer could be freed in the decompression code.
CVE-2009-1722
A buffer overflow was discovered in the compression code.
For the old stable distribution (etch), these problems have been fixed in version 1.2.2-4.3+etch2.
For the stable distribution (lenny), these problems have been fixed in version 1.6.1-3+lenny3.
For the unstable distribution (sid), these problems will be fixed soon.
We recommend that you upgrade your openexr packages.
Severity
Classification
-
CVE CVE-2009-1720, CVE-2009-1721, CVE-2009-1722 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities