CVE-2021-45942: Buffer Overflow
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf31::LineCompositeTask::execute (called from IlmThread31::NullThreadPoolProvider::addTask and IlmThread31::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-45942?
CVE-2021-45942 is a vulnerability in OpenEXR 3.1.x before 3.1.4 that allows a heap-based buffer overflow in the execute function of the LineCompositeTask class.
What is the severity of CVE-2021-45942?
CVE-2021-45942 has a severity rating of 5.5 (medium).
How does CVE-2021-45942 affect OpenEXR?
CVE-2021-45942 affects OpenEXR versions 3.1.x before 3.1.4.
How can I fix CVE-2021-45942?
To fix CVE-2021-45942, update OpenEXR to version 3.1.4 or later.
Where can I find more information about CVE-2021-45942?
You can find more information about CVE-2021-45942 at the following references: [Reference 1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41416), [Reference 2](https://github.com/AcademySoftwareFoundation/openexr/blob/v3.1.4/CHANGES.md#version-314-january-26-2022), [Reference 3](https://github.com/AcademySoftwareFoundation/openexr/commit/11cad77da87c4fa2aab7d58dd5339e254db7937e).