Added |
CVSS V3.1 |
|
NIST AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
Added |
CVSS V2 |
|
NIST (AV:N/AC:M/Au:N/C:N/I:N/A:P)
|
Added |
CWE |
|
NIST CWE-787
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* versions from (including) 3.1.0 up to (including) 3.1.3
|
Changed |
Reference Type |
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41416 No Types Assigned
|
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41416 Exploit, Issue Tracking, Mailing List, Patch, Third Party Advisory
|
Changed |
Reference Type |
https://github.com/AcademySoftwareFoundation/openexr/commit/11cad77da87c4fa2aab7d58dd5339e254db7937e No Types Assigned
|
https://github.com/AcademySoftwareFoundation/openexr/commit/11cad77da87c4fa2aab7d58dd5339e254db7937e Patch, Third Party Advisory
|
Changed |
Reference Type |
https://github.com/AcademySoftwareFoundation/openexr/commit/db217f29dfb24f6b4b5100c24ac5e7490e1c57d0 No Types Assigned
|
https://github.com/AcademySoftwareFoundation/openexr/commit/db217f29dfb24f6b4b5100c24ac5e7490e1c57d0 Patch, Third Party Advisory
|
Changed |
Reference Type |
https://github.com/AcademySoftwareFoundation/openexr/pull/1209 No Types Assigned
|
https://github.com/AcademySoftwareFoundation/openexr/pull/1209 Exploit, Patch, Third Party Advisory
|
Changed |
Reference Type |
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openexr/OSV-2021-1627.yaml No Types Assigned
|
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/openexr/OSV-2021-1627.yaml Third Party Advisory
|
Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism
|