Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5841

Опубликовано: 01 фев. 2024
Источник: debian
EPSS Низкий

Описание

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openexrfixed3.1.13-1package
openexrno-dsabookwormpackage
openexrnot-affectedbullseyepackage
openexrnot-affectedbusterpackage

Примечания

  • https://takeonme.org/cves/CVE-2023-5841.html

  • https://github.com/AcademySoftwareFoundation/openexr/issues/1625

  • https://github.com/AcademySoftwareFoundation/openexr/commit/46944c3a87ebc6c5d9a9a4962a94569ba1082bc3

  • https://github.com/AcademySoftwareFoundation/openexr/pull/1627

EPSS

Процентиль: 64%
0.00483
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 1 года назад

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVSS3: 9.1
redhat
больше 1 года назад

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVSS3: 9.1
nvd
больше 1 года назад

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

rocky
7 месяцев назад

Important: openexr security update

rocky
7 месяцев назад

Important: openexr security update

EPSS

Процентиль: 64%
0.00483
Низкий