Bug 1205021 (CVE-2022-41838) - VUL-0: CVE-2022-41838: OpenImageIO: DDS: crash when processing cubemap files and a cube face was not present
Summary: VUL-0: CVE-2022-41838: OpenImageIO: DDS: crash when processing cubemap files ...
Status: REOPENED
Alias: CVE-2022-41838
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.4
Hardware: Other Other
: P3 - Medium : Minor (vote)
Target Milestone: ---
Assignee: Hans-Peter Jansen
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/347024/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-11-04 07:33 UTC by Carlos López
Modified: 2022-11-04 10:05 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-11-04 07:33:21 UTC
rh#2139797

From https://github.com/OpenImageIO/oiio/releases/tag/v2.3.21.0:

RLA: fix potential buffer overrun. (TALOS-2022-1629, CVE-2022-36354) #3624
TIFF: guard against corrupt files with buffer overflows. (TALOS-2022-1627,
CVE-2022-41977) #3628
TIFF: guard against buffer overflow for certain CMYK files.
(TALOS-2022-1633, CVE-2022-41639) (TALOS-2022-1643, CVE-2022-41988) #3632

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2139797
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41838
Comment 2 Carlos López 2022-11-04 07:44:28 UTC
(In reply to Carlos López from comment #0)
> RLA: fix potential buffer overrun. (TALOS-2022-1629, CVE-2022-36354) #3624
> TIFF: guard against corrupt files with buffer overflows. (TALOS-2022-1627,
> CVE-2022-41977) #3628
> TIFF: guard against buffer overflow for certain CMYK files.
> (TALOS-2022-1633, CVE-2022-41639) (TALOS-2022-1643, CVE-2022-41988) #3632

Please ignore this, it is not relevant. The fix appeared in this changelog entry:
https://github.com/OpenImageIO/oiio/releases/tag/v2.4.5.0
Comment 3 Hans-Peter Jansen 2022-11-04 09:30:03 UTC
I love self-solving problems ;-)
Comment 4 Carlos López 2022-11-04 10:05:55 UTC
(In reply to Hans-Peter Jansen from comment #3)
> I love self-solving problems ;-)

Unsure why you think this is already solved, the patch is applicable on Factory, but even if that is the case please just reassign to security-team, don't close the bug