PT-2020-6398 · Openexr+1 · Openexr+1

Pedro Sampaio

·

Published

2020-11-29

·

Updated

2023-10-17

·

CVE-2021-23169

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions prior to 3.0.1
Description A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR. This issue allows an attacker to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR, potentially leading to unauthorized access to confidential data, disruption of data integrity, and denial of service.
Recommendations For OpenEXR versions prior to 3.0.1, update to version 3.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the copyIntoFrameBuffer function until a patch is available. Restrict access to applications compiled against OpenEXR to minimize the risk of exploitation.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1408
AZL-44256
BDU:2021-04603
CVE-2021-23169
MGASA-2021-0326
OESA-2021-1238
ROSA-SA-2023-2247

Affected Products

Alt Linux
Openexr