CVE-2021-3933: Integer Overflow
A vulnerability was found in openexr where an Integer-overflow was found in Imf31::bytesPerDeepLineTable.
References: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=38912
Other sources
An integer overflow could occur when OpenEXR processes a crafted file on systems where sizet < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3933?
CVE-2021-3933 is a vulnerability that could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits.
What is the severity of CVE-2021-3933?
CVE-2021-3933 has a severity rating of medium with a score of 5.5.
Which software is affected by CVE-2021-3933?
OpenEXR versions 2.2.1-4.1+deb10u2, 2.5.4-2+deb11u1, 3.1.5-5, and 3.1.5-5.1 are affected on Debian. OpenEXR versions up to 3.1.2 are affected on other systems.
How can I fix CVE-2021-3933 on Debian?
To fix CVE-2021-3933 on Debian, update the OpenEXR package to version 2.2.1-4.1+deb10u2 or higher.
Is Fedora affected by CVE-2021-3933?
Yes, Fedora version 36 is affected by CVE-2021-3933.