CVE-2021-3474: Integer Overflow
There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
Other sources
Undefined-shift in Imf25::FastHufDecoder::FastHufDecoder
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/OpenEXRto a version that resolves this vulnerability.Fixed in 3.0.0 - Upgrade
Upgrade
redhat/OpenEXRto a version that resolves this vulnerability.Fixed in 2.4.3 - Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.0.0-beta
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3474.
What is the title of this vulnerability?
The title of this vulnerability is 'Flaw in OpenEXR before 3.0.0-beta causing shift overflow in FastHufDecoder.'
What is the severity of CVE-2021-3474?
The severity of CVE-2021-3474 is medium with a CVSS score of 5.3.
Which software versions are affected by this vulnerability?
OpenEXR versions up to exclusive 2.4.3 and between inclusive-exclusive 2.5.0 to 2.5.4 are affected, as well as Debian Linux versions 9.0 and 10.0.
How can this vulnerability be exploited?
A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.