Vulnerability CVE-2021-3598: Information

Description

There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.

Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: July 6, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-119

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
openexrsisyphus3.1.5-alt13.1.5-alt2.2ALT-PU-2023-1408-1314595Fixed
openexrsisyphus_e2k3.1.5-alt2.13.1.5-alt2.2ALT-PU-2023-2963-1-Fixed
openexrsisyphus_riscv643.1.5-alt23.1.5-alt2.2ALT-PU-2023-3190-1-Fixed
openexrc9f22.3.0-alt1.c9f2.12.3.0-alt1.c9f2.1ALT-PU-2021-3360-1290376Fixed
openexrp113.1.5-alt13.1.5-alt2.2ALT-PU-2023-1408-1314595Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1970987
  • Exploit
  • Issue Tracking
  • Patch
  • Third Party Advisory
GLSA-202210-31
  • Third Party Advisory
DSA-5299
  • Third Party Advisory
[debian-lts-announce] 20221211 [SECURITY] [DLA 3236-1] openexr security update
  • Mailing List
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
      End excliding
      3.0.5

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*