CVE-2021-23169
Summary
| CVE | CVE-2021-23169 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-08 12:15:00 UTC |
| Updated | 2023-11-07 03:30:00 UTC |
| Description | A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: mingw-openexr-2.5.5-2.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: mingw-openexr-2.5.5-2.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: mingw-OpenEXR-2.4.1-4.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 1947612 – (CVE-2021-23169) CVE-2021-23169 OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer |
MISC |
bugzilla.redhat.com |
|
| OpenEXR: Multiple Vulnerabilities (GLSA 202210-31) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 33 Update: mingw-OpenEXR-2.4.1-4.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179744 Debian Security Update for openexr (CVE-2021-23169)
- 281212 Fedora Security Update for mingw (FEDORA-2021-6af32bfcd2)
- 281213 Fedora Security Update for mingw (FEDORA-2021-c194de7719)
- 502134 Alpine Linux Security Update for openexr
- 710663 Gentoo Linux OpenEXR Multiple Vulnerabilities (GLSA 202210-31)