ZeroHour

CVE-2021-45942

PoC ×2
CVSS 3.1
5.5 medium
EPSS
2%p77
Published
()
Modified
Description

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

Vendors
openexrfedoraprojectdebian
Products
openexr, fedora, debian linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.