CVE-2021-23215: Buffer Overflow
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
Other sources
Integer-overflow in Imf25::DwaCompressor::initializeBuffers
References:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29653
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23215?
CVE-2021-23215 is an integer overflow leading to a heap-buffer overflow vulnerability found in the DwaCompressor of OpenEXR in versions before 3.0.1.
How severe is CVE-2021-23215?
CVE-2021-23215 has a severity rating of 5.5, which is considered medium.
Which software versions are affected by CVE-2021-23215?
OpenEXR versions before 3.0.1 are affected by CVE-2021-23215.
How can an attacker exploit CVE-2021-23215?
An attacker could exploit CVE-2021-23215 to crash an application compiled with OpenEXR.
Are there any patches or fixes available for CVE-2021-23215?
Yes, the OpenEXR version 3.0.1 contains the fix for CVE-2021-23215.