PT-2020-6982 · Openexr+3 · Openexr+3

Michael Kaplan

·

Published

2020-09-24

·

Updated

2023-03-10

·

CVE-2021-20298

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenEXR (affected versions not specified)
Description The issue is related to a buffer overflow in the B44Compressor component of OpenEXR, which is used for storing images with high dynamic range. An attacker can exploit this by submitting a specially crafted file, potentially leading to a denial of service. The highest threat from this issue is to system availability, as it allows an attacker to exhaust all accessible memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1408
BDU:2024-07289
CVE-2021-20298
DLA-3236-1
OESA-2022-1884
OESA-2022-1885
OPENSUSE-SU-2021:1198-1
OPENSUSE-SU-2021:2793-1
OPENSUSE-SU-2021_1198-1
OPENSUSE-SU-2021_2793-1
SUSE-SU-2021:14846-1
SUSE-SU-2021:2793-1
SUSE-SU-2021:2913-1
SUSE-SU-2021_14846-1
SUSE-SU-2021_2793-1
SUSE-SU-2021_2913-1

Affected Products

Alt Linux
Astra Linux
Openexr
Suse