unofficial mirror of bug-guix@gnu.org 
 help / color / mirror / code / Atom feed
* bug#70174: OpenEXR is vulnerable to CVE-2023-5841 and CVE-2021-45942
@ 2024-04-04  1:07 Vinicius Monego
  2024-04-04  2:50 ` John Kehayias via Bug reports for GNU Guix
  0 siblings, 1 reply; 4+ messages in thread
From: Vinicius Monego @ 2024-04-04  1:07 UTC (permalink / raw)
  To: 70174

OpenEXR suffers from these vulnerabilities which were fixed in version 
3.2.2 [1] and 3.1.4 [2], respectively, while our version is currently 3.1.3.

The package contains 448 dependents, and a change in derivation 
shouldn't be pushed to master, at least according to the patch 
submission guidelines.

[1] https://nvd.nist.gov/vuln/detail/CVE-2023-5841

[2] https://nvd.nist.gov/vuln/detail/CVE-2021-45942





^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2024-04-18  5:00 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-04-04  1:07 bug#70174: OpenEXR is vulnerable to CVE-2023-5841 and CVE-2021-45942 Vinicius Monego
2024-04-04  2:50 ` John Kehayias via Bug reports for GNU Guix
2024-04-04  3:47   ` John Kehayias via Bug reports for GNU Guix
2024-04-18  4:58     ` John Kehayias via Bug reports for GNU Guix

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).