CVE-2021-3475: Integer Overflow
Integer-overflow in Imf25::calculateNumTiles
Other sources
There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/OpenEXRto a version that resolves this vulnerability.Fixed in 3.0.0 - Upgrade
Upgrade
redhat/OpenEXRto a version that resolves this vulnerability.Fixed in 2.4.3 - Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.0.0-beta
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in OpenEXR?
The vulnerability ID for this flaw in OpenEXR is CVE-2021-3475.
What is the severity level of CVE-2021-3475?
The severity level of CVE-2021-3475 is medium with a severity value of 5.3.
Which versions of OpenEXR are affected by CVE-2021-3475?
Versions before 3.0.0-beta of OpenEXR are affected by CVE-2021-3475.
What is the potential impact of CVE-2021-3475?
CVE-2021-3475 could potentially lead to problems with application availability due to an integer overflow caused by a crafted file.
How can I fix CVE-2021-3475?
To fix CVE-2021-3475, users should update to version 3.0.0-beta or later of OpenEXR.