CVE-2021-20303
published 2022-03-04CVE-2021-20303: A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could…
PriorityP424medium6.1CVSS 3.1
AVLACLPRNUIRSUCNILAH
EPSS
0.81%
52.8th percentile
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openexr | < openexr 2.5.4-1 (bookworm) | openexr 2.5.4-1 (bookworm) |
| openexr | openexr | < 2.5.4 | 2.5.4 |
| openexr | openexr | — | — |
| openexr | openexr | >= 0 < 2.5.4-1 | 2.5.4-1 |
| openexr | openexr | >= 0 < 2.5.4-1 | 2.5.4-1 |
| openexr | openexr | >= 0 < 2.5.4-1 | 2.5.4-1 |
| openexr | openexr | >= 0 < 2.5.4-1 | 2.5.4-1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
vendor_redhat·2021-02-15·CVSS 6.1
CVE-2021-20303 [MEDIUM] CWE-190 OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
There is a flaw in OpenEXR's dataWindowForTile function. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
Package: OpenEXR (Red Hat Enterprise Linux 6) - Out
Debian
CVE-2021-20303: openexr - A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An atta...
vendor_debian·2021·CVSS 6.1
CVE-2021-20303 [MEDIUM] CVE-2021-20303: openexr - A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An atta...
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: resolved (fixed in 2.5.4-1)
forky: resolved (fixed in 2.5.4-1)
sid: resolved (fixed in 2.5.4-1)
trixie: resolved (fixed in 2.5.4-1)
GHSA
GHSA-vhq7-5jv5-9gwf: A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc
ghsa_unreviewed·2022-03-05
CVE-2021-20303 [MEDIUM] CWE-190 GHSA-vhq7-5jv5-9gwf: A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
OSV
CVE-2021-20303: A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc
osv·2022-03-04·CVSS 6.1
CVE-2021-20303 [MEDIUM] CVE-2021-20303: A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=25505https://bugzilla.redhat.com/show_bug.cgi?id=1939151https://github.com/AcademySoftwareFoundation/openexr/pull/831https://lists.debian.org/debian-lts-announce/2022/12/msg00022.htmlhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=25505https://bugzilla.redhat.com/show_bug.cgi?id=1939151https://github.com/AcademySoftwareFoundation/openexr/pull/831https://lists.debian.org/debian-lts-announce/2022/12/msg00022.html
2022-03-04
Published