PT-2020-5885 · Openexr+5 · Openexr+5

Michael Kaplan

·

Published

2020-09-02

·

Updated

2023-10-17

·

CVE-2021-3479

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: OpenEXR versions prior to 3.0.0-beta
Description: The issue is related to a flaw in OpenEXR's Scanline API functionality, which can lead to excessive consumption of memory when a crafted file is processed. This can result in an impact to system availability. An attacker who can submit a specially crafted file to be processed by OpenEXR could exploit this issue.
Recommendations: For versions prior to 3.0.0-beta, update to version 3.0.0-beta or later to resolve the issue. As a temporary workaround, consider restricting the processing of crafted files to minimize the risk of exploitation. Avoid using the Scanline API functionality with untrusted input until the issue is resolved.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1863
ALT-PU-2021-1864
ALT-PU-2021-1933
ALT-PU-2021-1934
AZL-44244
BDU:2021-01975
CVE-2021-3479
DLA-2701-1
DLA-3236-1
MGASA-2021-0326
OESA-2021-1167
OPENSUSE-SU-2021:0670-1
OPENSUSE-SU-2021_0670-1
ROSA-SA-2023-2248
SUSE-SU-2021:14757-1
SUSE-SU-2021:1489-1
SUSE-SU-2021:2159-1
SUSE-SU-2021_14757-1
SUSE-SU-2021_1489-1
SUSE-SU-2021_2159-1
USN-4900-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Openexr
Suse
Ubuntu