Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45942

Опубликовано: 01 янв. 2022
Источник: redhat
CVSS3: 5.5

Описание

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

A heap-based-buffer-overflow vulnerability was found in OpenEXR's composite_line() function in the 'ImfCompositeDeepScanLine.cpp' file. This flaw allows an attacker to pass a specially crafted file to OpenEXR, by tricking the victim into opening it, triggering a heap-based buffer overflow. This leads to memory corruption and allows an attacker to cause a denial of service.

Отчет

This vulnerability does not affect Red Hat Enterprise Linux 6 and 7 because they are shipped with OpenEXR v1.6.1 and v1.7.1 respectively, and the vulnerable code is not present in the code-base.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6OpenEXRNot affected
Red Hat Enterprise Linux 7OpenEXRNot affected
Red Hat Enterprise Linux 8OpenEXRWill not fix
Red Hat Enterprise Linux 9openexrWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2047745OpenEXR: heap-based buffer overflow in Imf_3_1:LineCompositeTask:execute

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

CVSS3: 5.5
nvd
около 4 лет назад

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

CVSS3: 5.5
debian
около 4 лет назад

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1 ...

suse-cvrf
почти 4 года назад

Security update for openexr

suse-cvrf
около 4 лет назад

Security update for openexr

5.5 Medium

CVSS3