CVE-2021-3478

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
31/03/2021
Last modified:
13/12/2022

Description

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* 2.4.3 (excluding)
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.4 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*