CVE-2022-34300
Dashboard / Vulnerabilities / CVE-2022-34300
CVE-2022-34300
Summary:
Details: In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34300.json, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSGENQ3UEQ6QEKW45FLZFGXPCD5IHXFM/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I4YMGAN6AV4H4HPDINUHBKX7XE4T5THF/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JFCXR2EJGIE24DV45AWX6JJM7RQAT5CY/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQCZL36LTOHWCQ25R5WTRSD5QMM436Q6/, https://nvd.nist.gov/vuln/detail/CVE-2022-34300, https://github.com/syoyo/tinyexr/issues/167
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
