{"id":"CVE-2021-45942","details":"OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.","modified":"2026-05-16T03:55:56.664351138Z","published":"2022-01-01T01:15:09.043Z","related":["SUSE-SU-2022:0061-1","SUSE-SU-2022:0062-1","SUSE-SU-2022:0062-2","openSUSE-SU-2022:0062-1","openSUSE-SU-2024:11712-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"],"vendor_product":"debian:debian_linux","source":"CPE_FIELD","extracted_events":[{"last_affected":"10.0"},{"last_affected":"11.0"}]},{"cpes":["cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*"],"vendor_product":"fedoraproject:fedora","source":"CPE_FIELD","extracted_events":[{"last_affected":"34"},{"last_affected":"35"},{"last_affected":"36"}]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6TEZDE2S2DB4BF4LZSSV4W3DNW7DSRHJ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HJ5PW4WNXBKCRFGDZGAQOSVH2BKZKL4X/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XJUK7WIQV5EKWTCZBRXFN6INHG6MLS5O/"},{"type":"ADVISORY","url":"https://github.com/AcademySoftwareFoundation/openexr/blob/v3.1.4/CHANGES.md#version-314-january-26-2022"},{"type":"ADVISORY","url":"https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.1.4"},{"type":"ADVISORY","url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openexr/OSV-2021-1627.yaml"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/12/msg00022.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202210-31"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5299"},{"type":"FIX","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41416"},{"type":"FIX","url":"https://github.com/AcademySoftwareFoundation/openexr/commit/11cad77da87c4fa2aab7d58dd5339e254db7937e"},{"type":"FIX","url":"https://github.com/AcademySoftwareFoundation/openexr/commit/db217f29dfb24f6b4b5100c24ac5e7490e1c57d0"},{"type":"FIX","url":"https://github.com/AcademySoftwareFoundation/openexr/pull/1209"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}