FreeBSD : OpenEXR -- multiple remote code execution and denial of service vulnerabilities (803879e9-4195-11e7-9b08-080027ef73ec)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

Brandon Perry reports :

[There] is a zip file of EXR images that cause segmentation faults in
the OpenEXR library (tested against 2.2.0).

- CVE-2017-9110 In OpenEXR 2.2.0, an invalid read of size 2 in the
hufDecode function in ImfHuf.cpp could cause the application to crash.

- CVE-2017-9111 In OpenEXR 2.2.0, an invalid write of size 8 in the
storeSSE function in ImfOptimizedPixelReading.h could cause the
application to crash or execute arbitrary code.

- CVE-2017-9112 In OpenEXR 2.2.0, an invalid read of size 1 in the
getBits function in ImfHuf.cpp could cause the application to crash.

- CVE-2017-9113 In OpenEXR 2.2.0, an invalid write of size 1 in the
bufferedReadPixels function in ImfInputFile.cpp could cause the
application to crash or execute arbitrary code.

- CVE-2017-9114 In OpenEXR 2.2.0, an invalid read of size 1 in the
refill function in ImfFastHuf.cpp could cause the application to
crash.

- CVE-2017-9115 In OpenEXR 2.2.0, an invalid write of size 2 in the =
operator function in half.h could cause the application to crash or
execute arbitrary code.

- CVE-2017-9116 In OpenEXR 2.2.0, an invalid read of size 1 in the
uncompress function in ImfZip.cpp could cause the application to
crash.

See also :

http://www.openwall.com/lists/oss-security/2017/05/12/5
https://github.com/openexr/openexr/issues/232
http://www.nessus.org/u?a241e53c

Solution :

Update the affected package.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 100442 ()

Bugtraq ID:

CVE ID: CVE-2017-9110
CVE-2017-9111
CVE-2017-9112
CVE-2017-9113
CVE-2017-9114
CVE-2017-9115
CVE-2017-9116

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now