Advisories ยป MGASA-2022-0020

Updated openexr packages fix security vulnerability

Publication date: 16 Jan 2022
Modification date: 16 Jan 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-45942

Description

OpenEXR 3.1.0 through 3.1.3 has a heap-based buffer overflow in
Imf_3_1::LineCompositeTask::execute (called from 
IlmThread_3_1::NullThreadPoolProvider::addTask and 
IlmThread_3_1::ThreadPool::addGlobalTask). (CVE-2021-45942)
                

References

SRPMS

8/core