| Type | URI |
|---|---|
| Issue Tracking | https://bugzilla.redhat.com/show_bug.cgi?id=1939159 |
| Third Party Advisory | https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26956 |
| MLIST | https://lists.debian.org/debian-lts-announce/2021/07/msg00001.html |
| GENTOO | https://security.gentoo.org/glsa/202107-27 |
| CPE URI | Source package | Min version | Max version |
|---|---|---|---|
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* |
openexr | >= None | <= 2.5.5 |
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* |
openexr | >= None | < 2.4.3 |
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* |
openexr | >= 2.5.0 | < 2.5.4 |
| Source package | Branch | Version | Maintainer | Status |
|---|---|---|---|---|
| openexr | edge-community | 2.5.5-r3 | Mark Riedesel <mark+alpine@klowner.com> | fixed |
| openexr | edge-community | 2.5.4-r0 | None | fixed |
| openexr | edge-community | 2.5.2-r0 | None | possibly vulnerable |
| openexr | edge-community | 2.4.1-r0 | None | possibly vulnerable |
| openexr | edge-community | 2.4.0-r0 | None | possibly vulnerable |
| openexr | edge-community | 2.2.1-r0 | None | possibly vulnerable |
| openexr | 3.22-community | 2.5.4-r0 | None | fixed |
| openexr | 3.22-community | 2.5.2-r0 | None | possibly vulnerable |
| openexr | 3.22-community | 2.4.1-r0 | None | possibly vulnerable |
| openexr | 3.22-community | 2.4.0-r0 | None | possibly vulnerable |
| openexr | 3.22-community | 2.2.1-r0 | None | possibly vulnerable |
| openexr | 3.21-community | 2.5.4-r0 | None | fixed |
| openexr | 3.20-community | 2.5.4-r0 | None | fixed |
| openexr | 3.19-community | 2.5.4-r0 | None | fixed |
| openexr | 3.18-community | 2.5.4-r0 | None | fixed |
| openexr | 3.17-community | 2.5.4-r0 | None | fixed |