CVE-2021-45942
moderate-risk
Published 2022-01-01
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
Do I need to act?
-
0.62% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
LOCAL
/ LOW complexity
Affected Products (6)
Affected Vendors
References (26)
Third Party Advisory
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openexr/OSV-2021-1627.y...
Third Party Advisory
https://security.gentoo.org/glsa/202210-31
Third Party Advisory
https://www.debian.org/security/2022/dsa-5299
Third Party Advisory
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openexr/OSV-2021-1627.y...
and 6 more references
33
/ 100
moderate-risk
Severity
18/34 · Moderate
Exploitability
2/34 · Minimal
Exposure
13/34 · Low