Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2021-45942

Published: 1 January 2022

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

Priority

Low

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
openexr
Launchpad, Ubuntu, Debian
bionic Needed

focal Needed

hirsute Ignored
(end of life)
kinetic Ignored
(end of life, was needed)
lunar Needed

trusty Ignored
(end of standard support)
upstream Needs triage

xenial Needs triage

impish Ignored
(end of life)
jammy Needed

Patches:
upstream: https://github.com/AcademySoftwareFoundation/openexr/commit/db217f29dfb24f6b4b5100c24ac5e7490e1c57d0 (no?)
upstream: https://github.com/AcademySoftwareFoundation/openexr/commit/11cad77da87c4fa2aab7d58dd5339e254db7937e

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H