CVE-2021-20298: High severity openexr vulnerability
A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.
Other sources
Out-of-memory in openexrexrenvmapfuzzer
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-20298?
CVE-2021-20298 is a vulnerability found in OpenEXR's B44Compressor that allows an attacker to exhaust all accessible memory by submitting a crafted file.
What is the severity of CVE-2021-20298?
The severity of CVE-2021-20298 is high with a CVSS score of 7.5.
Which software is affected by CVE-2021-20298?
OpenEXR version 2.5.7, Debian Linux version 10.0, and Red Hat OpenEXR version up to 3.0.0 are affected by CVE-2021-20298.
How can an attacker exploit CVE-2021-20298?
An attacker can exploit CVE-2021-20298 by submitting a crafted file to be processed by OpenEXR, which will exhaust all accessible memory.
Is there a fix for CVE-2021-20298?
Yes, the fix for CVE-2021-20298 is to update to OpenEXR version 3.0.0.