PT-2020-5892 · Openexr+5 · Openexr+5

Michael Kaplan

·

Published

2020-08-17

·

Updated

2023-10-17

·

CVE-2021-3474

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: OpenEXR versions prior to 3.0.0-beta
Description: The issue is related to a flaw in the FastHufDecoder function of the OpenEXR library, which can cause a shift overflow when processing crafted input files. This could potentially lead to problems with application availability, such as a denial of service. The vulnerability can be exploited by a remote attacker by opening specially crafted EXR files.
Recommendations: For OpenEXR versions prior to 3.0.0-beta, update to version 3.0.0-beta or later to resolve the issue. As a temporary workaround, consider restricting the use of the FastHufDecoder function until a patch is available. Avoid processing untrusted input files with OpenEXR to minimize the risk of exploitation.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1863
ALT-PU-2021-1864
ALT-PU-2021-1933
ALT-PU-2021-1934
AZL-44640
BDU:2021-01984
CVE-2021-3474
DLA-2701-1
DLA-3236-1
MGASA-2021-0326
OESA-2021-1167
OPENSUSE-SU-2021:0536-1
OPENSUSE-SU-2021_0536-1
ROSA-SA-2023-2247
SUSE-SU-2021:1097-1
SUSE-SU-2021_1097-1
USN-4900-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Openexr
Suse
Ubuntu