Summary
The remote host is missing an update to OpenEXR
announced via advisory FEDORA-2009-8136.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update OpenEXR' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-8136
Insight
OpenEXR is a high dynamic-range (HDR) image file format developed by Industrial Light & Magic for use in computer imaging applications. This package contains libraries and sample applications for handling the format.
ChangeLog:
* Wed Jul 29 2009 Rex Dieter 1.6.1-8
- CVE-2009-1720 OpenEXR: Multiple integer overflows (#513995) - CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression (#514003) * Fri Jul 24 2009 Fedora Release Engineering - 1.6.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Feb 23 2009 Fedora Release Engineering - 1.6.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Fri Dec 12 2008 Caolán McNamara 1.6.1-5
- rebuild to get provides pkgconfig(OpenEXR)
References
Severity
Classification
-
CVE CVE-2009-1720, CVE-2009-1721 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities