First published: Thu Apr 08 2021(Updated: )
An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openexr Openexr | <3.0.1 | |
redhat/OpenEXR | <3.0.1 | 3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this OpenEXR vulnerability is CVE-2021-26945.
The severity of CVE-2021-26945 is medium.
CVE-2021-26945 can lead to a heap-buffer overflow and crash an application compiled with OpenEXR.
Versions of OpenEXR before 3.0.1 are affected by CVE-2021-26945.
Yes, updating to OpenEXR version 3.0.1 or later will fix CVE-2021-26945.