Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e527bcc8 by Salvatore Bonaccorso at 2026-08-22T13:32:59+02:00
Track fixes for openexr via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -63687,7 +63687,7 @@ CVE-2026-47633 (Exposure of sensitive information to an 
unauthorized actor in Co
 CVE-2026-46699 (conda-smithy is a tool for combining a conda recipe with 
configuration ...)
        NOT-FOR-US: conda-smithy
 CVE-2026-45696 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
-       - openexr <unfixed>
+       - openexr 3.4.14-0.1
        [trixie] - openexr <not-affected> (Vulnerable code not present)
        [bookworm] - openexr <not-affected> (Vulnerable code not present)
        [bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -63696,7 +63696,7 @@ CVE-2026-45696 (OpenEXR is the reference implementation 
and specification for th
        NOTE: Introduced by 
https://github.com/AcademySoftwareFoundation/openexr/commit/50ba96b1dbe353a98a626c7fd0ff1e50cc8c188f
 (v3.4-alpha)
        NOTE: Fixed by: by 
https://github.com/AcademySoftwareFoundation/openexr/commit/c7af2d233b7b2a4452c11f26cf47584cc2b35721
 (v3.4.13-rc)
 CVE-2026-44663 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
-       - openexr <unfixed>
+       - openexr 3.4.14-0.1
        [trixie] - openexr <not-affected> (Vulnerable code not present)
        [bookworm] - openexr <not-affected> (Vulnerable code not present)
        [bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -94190,12 +94190,12 @@ CVE-2026-43576 (OpenClaw before 2026.4.5 contains a 
server-side request forgery
 CVE-2026-43575 (OpenClaw versions 2026.2.21 before 2026.4.10 contain an 
authentication ...)
        NOT-FOR-US: OpenClaw
 CVE-2026-42217 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1136001)
+       - openexr 3.4.14-0.1 (bug #1136001)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3c67-4wwp-w52m
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2378
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/21eaa33bcbbb0c83a5fc42f6b6d65b70a996e63c
 CVE-2026-42216 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1136001)
+       - openexr 3.4.14-0.1 (bug #1136001)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-65j8-95g9-jgj4
 CVE-2026-42194 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
        NOT-FOR-US: Admidio
@@ -94293,7 +94293,7 @@ CVE-2026-41201 (CI4MS is a CodeIgniter 4-based CMS 
skeleton that delivers a prod
 CVE-2026-41143 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.1, YesWi ...)
        NOT-FOR-US: YesWiki
 CVE-2026-41142 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1135946)
+       - openexr 3.4.14-0.1 (bug #1135946)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m25w-72cj-q6mg
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2367
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/0592ee539f33c122c90f09238579b902d838afb4
 (main)
@@ -104930,14 +104930,14 @@ CVE-2026-40279 (BACnet Stack is a BACnet open 
source protocol stack C library fo
 CVE-2026-40264 (OpenBao is an open source identity-based secrets management 
system. Op ...)
        - openbao <itp> (bug #1069794)
 CVE-2026-40250 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1134642)
+       - openexr 3.4.14-0.1 (bug #1134642)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m5qw-23x2-6phj
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2346
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/416fecf71241c097d52da5b219d36afd94800e69
 (main)
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/42d394a7b761325a3df7c2d57f9dfd905629ca4f
 (v3.4.10-rc)
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/a41f0d19841469148aabf7e1e056fab9f1c3c4f0
 (v3.2.8-rc)
 CVE-2026-40244 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1134642)
+       - openexr 3.4.14-0.1 (bug #1134642)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-j526-66f6-fxhx
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2346
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/416fecf71241c097d52da5b219d36afd94800e69
 (main)
@@ -104964,7 +104964,7 @@ CVE-2026-39973 (Apktool is a tool for reverse 
engineering Android APK files. In
 CVE-2026-39946 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
        - openbao <itp> (bug #1069794)
 CVE-2026-39886 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1134642)
+       - openexr 3.4.14-0.1 (bug #1134642)
        [trixie] - openexr <not-affected> (Vulnerable code not present)
        [bookworm] - openexr <not-affected> (Vulnerable code not present)
        [bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -112821,14 +112821,14 @@ CVE-2026-34755 (vLLM is an inference and serving 
engine for large language model
 CVE-2026-34753 (vLLM is an inference and serving engine for large language 
models (LLM ...)
        - vllm <itp> (bug #1095237)
 CVE-2026-34589 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1133188)
+       - openexr 3.4.14-0.1 (bug #1133188)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p8xc-w3q4-h64x
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2328
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/e464a33cc5bcd9f7dad2364bf76c08a52a5b0fbf
 (main)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/ea588c8f075f5915e34931861e15b6c2d3b62561
 (v3.4.9-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/ca0139287918775e1fddc0ed0033d694bec033ff
 (v3.2.7-rc)
 CVE-2026-34588 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1133188)
+       - openexr 3.4.14-0.1 (bug #1133188)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-588r-cr5c-w6hf
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2329
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/7c31424f9e381f386af83194d0b0e253da4a24d2
 (main)
@@ -112843,21 +112843,21 @@ CVE-2026-34444 (Lupa integrates the runtimes of Lua 
or LuaJIT2 into CPython. In
 CVE-2026-34402
        REJECTED
 CVE-2026-34380 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1133188)
+       - openexr 3.4.14-0.1 (bug #1133188)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-q3v8-hw4m-59w5
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2323
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/f5beec2bd8636102e74460a0b624d3e26efc546f
 (main)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/b2cebfa1c68e76cb2048ac1c1fbf1b50d196ff9d
 (v3.4.9-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/a5e5a2eba975b57f77e1c6b6d22ecc49553624e2
 (v3.2.7-rc)
 CVE-2026-34379 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1133188)
+       - openexr 3.4.14-0.1 (bug #1133188)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-w88v-vqhq-5p24
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2324
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/3ad9b29430f9c2599dad113e1efe619a6ec7ba67
 (main)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/d32ffe9d3727c0474b63e91556baf61ced3d89e0
 (v3.4.9-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/76af7d7508819a477f2cbce808ee975da8053ce3
 (v3.2.7-rc)
 CVE-2026-34378 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1133188)
+       - openexr 3.4.14-0.1 (bug #1133188)
        [trixie] - openexr <not-affected> (Vulnerable code not present)
        [bookworm] - openexr <not-affected> (Vulnerable code not present)
        [bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -115041,15 +115041,15 @@ CVE-2026-34560 (CI4MS is a CodeIgniter 4-based CMS 
skeleton that delivers a prod
 CVE-2026-34559 (CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a 
production ...)
        NOT-FOR-US: CI4MS
 CVE-2026-34545 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1132578)
+       - openexr 3.4.14-0.1 (bug #1132578)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-ghfj-fx47-wg97
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/3827998f5c041d6a94c6af24bbb363daa669e4b3
 (v3.4.7-rc)
 CVE-2026-34544 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1132579)
+       - openexr 3.4.14-0.1 (bug #1132579)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-h762-rhv3-h25v
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/35e7aa35e22c1975606be86e859f31cc1fc598ee
 (v3.4.8-rc)
 CVE-2026-34543 (OpenEXR provides the specification and reference 
implementation of the ...)
-       - openexr <unfixed> (bug #1132580)
+       - openexr 3.4.14-0.1 (bug #1132580)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-vc68-257w-m432
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/openexr/commit/5f6d0aaa9e43802917af7db90f181e88e083d3b8
 (v3.4.8-rc)
 CVE-2026-34531 (Flask-HTTPAuth provides Basic, Digest and Token HTTP 
authentication fo ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e527bcc8c8bdc6f8fed4edae413b6f2af49b8eee

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e527bcc8c8bdc6f8fed4edae413b6f2af49b8eee
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to