CVE-2021-20304: Integer Overflow
A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be processed by OpenEXR, to trigger an undefined right shift error. The highest threat from this vulnerability is to system availability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-20304?
CVE-2021-20304 is a vulnerability found in OpenEXR's hufDecode functionality that allows an attacker to trigger an undefined right shift error by passing a crafted file to be processed by OpenEXR.
What is the severity of CVE-2021-20304?
CVE-2021-20304 has a severity rating of 7.5 (High).
How does CVE-2021-20304 affect OpenEXR?
CVE-2021-20304 affects OpenEXR versions up to and including 2.5.7 and OpenEXR version 3.0.0 on Red Hat systems.
How can an attacker exploit CVE-2021-20304?
An attacker can exploit CVE-2021-20304 by providing a specially crafted file to be processed by OpenEXR, triggering the undefined right shift error.
What is the highest threat from CVE-2021-20304?
The highest threat from CVE-2021-20304 is to system availability.