CVE-2021-3476: Integer Overflow
A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/OpenEXRto a version that resolves this vulnerability.Fixed in 3.0.0 - Upgrade
Upgrade
redhat/OpenEXRto a version that resolves this vulnerability.Fixed in 2.4.3 - Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.0.0-beta
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3476.
What is the title of the vulnerability?
The title of the vulnerability is 'A flaw in OpenEXR's B44 uncompression functionality'.
What is the severity level of CVE-2021-3476?
The severity level of CVE-2021-3476 is medium (5.3).
Which software versions are affected by CVE-2021-3476?
Versions before 3.0.0-beta of OpenEXR and specific versions (2.4.3, 2.5.0-2.5.4) of OpenEXR are affected.
How can the vulnerability be exploited?
An attacker who is able to submit a crafted file to OpenEXR can trigger shift overflows, potentially affecting application availability.