In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tinyexr | Tinyexr_project | 1.0.1 (including) | 1.0.1 (including) |
| Asymptote | Ubuntu | bionic | * |
| Asymptote | Ubuntu | focal | * |
| Asymptote | Ubuntu | impish | * |
| Asymptote | Ubuntu | kinetic | * |
| Asymptote | Ubuntu | lunar | * |
| Asymptote | Ubuntu | mantic | * |
| Asymptote | Ubuntu | oracular | * |
| Chromium-browser | Ubuntu | trusty | * |
| Chromium-browser | Ubuntu | upstream | * |
| Chromium-browser | Ubuntu | xenial | * |
| Godot | Ubuntu | focal | * |
| Godot | Ubuntu | impish | * |
| Godot | Ubuntu | kinetic | * |
| Godot | Ubuntu | lunar | * |
| Godot | Ubuntu | mantic | * |
| Goxel | Ubuntu | bionic | * |
| Goxel | Ubuntu | focal | * |
| Goxel | Ubuntu | impish | * |
| Goxel | Ubuntu | kinetic | * |
| Goxel | Ubuntu | lunar | * |
| Goxel | Ubuntu | mantic | * |
| Goxel | Ubuntu | oracular | * |
| Love | Ubuntu | bionic | * |
| Love | Ubuntu | focal | * |
| Love | Ubuntu | impish | * |
| Love | Ubuntu | kinetic | * |
| Love | Ubuntu | lunar | * |
| Love | Ubuntu | mantic | * |
| Love | Ubuntu | oracular | * |
| Mame | Ubuntu | bionic | * |
| Mame | Ubuntu | focal | * |
| Mame | Ubuntu | impish | * |
| Mame | Ubuntu | kinetic | * |
| Mame | Ubuntu | lunar | * |
| Mame | Ubuntu | mantic | * |
| Mame | Ubuntu | oracular | * |
| Psychtoolbox-3 | Ubuntu | bionic | * |
| Psychtoolbox-3 | Ubuntu | focal | * |
| Psychtoolbox-3 | Ubuntu | impish | * |
| Psychtoolbox-3 | Ubuntu | kinetic | * |
| Psychtoolbox-3 | Ubuntu | lunar | * |
| Psychtoolbox-3 | Ubuntu | mantic | * |
| Psychtoolbox-3 | Ubuntu | oracular | * |
| Qt6-webengine | Ubuntu | kinetic | * |
| Qt6-webengine | Ubuntu | lunar | * |
| Qt6-webengine | Ubuntu | mantic | * |
| Qt6-webengine | Ubuntu | oracular | * |
| Qtwebengine-opensource-src | Ubuntu | bionic | * |
| Qtwebengine-opensource-src | Ubuntu | focal | * |
| Qtwebengine-opensource-src | Ubuntu | impish | * |
| Qtwebengine-opensource-src | Ubuntu | kinetic | * |
| Qtwebengine-opensource-src | Ubuntu | lunar | * |
| Qtwebengine-opensource-src | Ubuntu | mantic | * |
| Qtwebengine-opensource-src | Ubuntu | oracular | * |
| Rbdoom3bfg | Ubuntu | bionic | * |
| Rbdoom3bfg | Ubuntu | focal | * |
| Rbdoom3bfg | Ubuntu | impish | * |
| Rbdoom3bfg | Ubuntu | kinetic | * |
| Rbdoom3bfg | Ubuntu | lunar | * |
| Rbdoom3bfg | Ubuntu | mantic | * |
| Rbdoom3bfg | Ubuntu | oracular | * |
| Renderdoc | Ubuntu | focal | * |
| Renderdoc | Ubuntu | impish | * |
| Renderdoc | Ubuntu | kinetic | * |
| Renderdoc | Ubuntu | lunar | * |
| Renderdoc | Ubuntu | mantic | * |
| Tinyexr | Ubuntu | impish | * |
| Tinyexr | Ubuntu | kinetic | * |
| Tinyexr | Ubuntu | lunar | * |
| Tinyexr | Ubuntu | mantic | * |
| Tinyexr | Ubuntu | oracular | * |