Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG][UNIX] #462

Open
mariamarutunian opened this issue Jul 9, 2024 · 1 comment
Open

[BUG][UNIX] #462

mariamarutunian opened this issue Jul 9, 2024 · 1 comment
Assignees
Labels
bug? reported as bug; triage pending

Comments

@mariamarutunian
Copy link

Summary

Vulnerabilities identified as CVE-2021-45942 and CVE-2021-20304 were discovered and fixed in OpenEXR's. However, related files are not updated in the POV-Ray project.

POV-Ray Version

Affected build version: < 3.7.0.10

Details

They were fixed on OpenEXR's with the following commits: - AcademySoftwareFoundation/openexr@db217f2
-, AcademySoftwareFoundation/openexr@51a92d6.
But, the POV-Ray project contains an old version of OpenEXR's.

References

Report Origin

The bug is reported by a tool developed at CAST.

@mariamarutunian mariamarutunian added the bug? reported as bug; triage pending label Jul 9, 2024
@chris20 chris20 self-assigned this Nov 10, 2024
@wfpokorny
Copy link
Contributor

Hi Chris,
On seeing you've self assigned this issue and #461, I thought to mention - that by default - Linux/Unix builds will use libraries which are installed as part of the linux/unix distribution. On my Ubuntu system, for example, the libraries shipped with the distribution are already patched.

The libraries which are code controlled and part of what one gets when one clones the POV-Ray repository are for windows builds. They perhaps need to be updated in any case, but I don't think #461 and #462 are Unix/Linux issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug? reported as bug; triage pending
Projects
None yet
Development

No branches or pull requests

3 participants