{"id":"CVE-2018-18444","details":"makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified other impact.","modified":"2026-04-09T06:12:25.207066Z","published":"2018-10-17T19:29:00.677Z","related":["MGASA-2019-0166","SUSE-SU-2019:0954-1","SUSE-SU-2019:1962-1","openSUSE-SU-2019:1265-1","openSUSE-SU-2024:11117-1"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5E2OZU4ZSF5W4ODBU4L547HX5A4WOBFV/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZN7WUH3SR6DSRODRB4SLFTBKP74FVC5/"},{"type":"WEB","url":"https://usn.ubuntu.com/4148-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4339-1/"},{"type":"WEB","url":"https://github.com/openexr/openexr/releases/tag/v2.4.0"},{"type":"EVIDENCE","url":"https://github.com/openexr/openexr/issues/351"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/AcademySoftwareFoundation/openexr","events":[{"introduced":"0"},{"last_affected":"0ac2ea34c8f3134148a5df4052e40f155b76f6fb"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"2.3.0"}]}},{"type":"GIT","repo":"https://github.com/academysoftwarefoundation/openexr","events":[{"introduced":"0"},{"fixed":"eae0e337c9f5117e78114fd05f7a415819df413a"}]}],"versions":["OPENEXR_1_0_4","v1.7.1","v2.0.0","v2.0.0.GM","v2.0.1","v2.1.0","v2.3.0","v2.4.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-18444.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}