makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Nov 8, 2019 | Oct 17, 2018 |
| Debian | — | Upgrade openexr | Jun 25, 2021 | Oct 17, 2018 |
| Freebsd | — | Upgrade ilmbaseUpgrade OpenEXR | Dec 30, 2019 | Dec 29, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 17, 2018 |
| Suse | — | Upgrade openexr-docUpgrade libilmimf-2_2-23-32bitUpgrade libIlmImfUtil-2_2-23Upgrade libIlmImf-Imf_2_1-21-32bitUpgrade libilmimfutil-2_2-23-32bitUpgrade OpenEXR-develUpgrade libIlmImf-2_2-23Upgrade openexrUpgrade libIlmImf-Imf_2_1-21 | Apr 25, 2019 | Oct 17, 2018 |
| Ubuntu | — | Upgrade openexrUpgrade libopenexr22Upgrade libopenexr24Upgrade libopenexr23 | Oct 8, 2019 | Oct 17, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub