UBUNTU-CVE-2023-5841

Source
https://ubuntu.com/security/CVE-2023-5841
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-5841.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-5841
Related
Published
2024-02-01T19:15:00Z
Modified
2024-11-20T12:17:18Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

References

Affected packages

Ubuntu:24.10 / openexr

Package

Name
openexr
Purl
pkg:deb/ubuntu/openexr?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.1.5-5.1build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / openexr

Package

Name
openexr
Purl
pkg:deb/ubuntu/openexr?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.1.5-5.1
3.1.5-5.1build1
3.1.5-5.1build2
3.1.5-5.1build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}