Back

MEDIUM

OpenEXR: Heap buffer overflow in the rleUncompress function

Published Aug 25, 2021

Description

There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Aug 25, 2021
Updated Aug 3, 2024
Reserved Jun 15, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Jun 11, 2021
Bugzilla 1970991

ENISA EUVD

Assigner redhat
Published Aug 25, 2021
Updated Aug 3, 2024

GitHub

No data