Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-45942

Опубликовано: 01 янв. 2022
Источник: debian

Описание

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openexrfixed3.1.4-1experimentalpackage
openexrfixed3.1.5-2package
openexrno-dsastretchpackage

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41416

  • https://github.com/AcademySoftwareFoundation/openexr/pull/1209

  • https://github.com/AcademySoftwareFoundation/openexr/commit/11cad77da87c4fa2aab7d58dd5339e254db7937e

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

CVSS3: 5.5
redhat
около 4 лет назад

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

CVSS3: 5.5
nvd
около 4 лет назад

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

suse-cvrf
почти 4 года назад

Security update for openexr

suse-cvrf
около 4 лет назад

Security update for openexr