CVE-2021-23169
published 2021-06-08CVE-2021-23169: A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.29%
81.3th percentile
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openexr | < openexr 2.5.4-2 (bookworm) | openexr 2.5.4-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openexr | openexr | < 3.0.1 | 3.0.1 |
| openexr | openexr | — | — |
| openexr | openexr | >= 0 < 2.5.4-2 | 2.5.4-2 |
| openexr | openexr | >= 0 < 2.5.4-2 | 2.5.4-2 |
| openexr | openexr | >= 0 < 2.5.4-2 | 2.5.4-2 |
| openexr | openexr | >= 0 < 2.5.4-2 | 2.5.4-2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
vendor_redhat·2021-03-17·CVSS 8.8
CVE-2021-23169 [HIGH] CWE-787 OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
OpenEXR: Heap-buffer-overflow in Imf_2_5::copyIntoFrameBuffer
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
Package: OpenEXR (Red Hat Enterprise Linux 6) - Out of support scope
Package: OpenEXR (Red Hat Enterprise Linux 7) - Will not fix
Package: gimp:flatpak/OpenEXR (Red Hat Enterprise Linux 8) - Will not fix
Package: OpenEXR (Red Hat Enterprise Linux 8) - Will not fi
Debian
CVE-2021-23169: openexr - A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR ...
vendor_debian·2021·CVSS 8.8
CVE-2021-23169 [HIGH] CVE-2021-23169: openexr - A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR ...
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
Scope: local
bookworm: resolved (fixed in 2.5.4-2)
bullseye: resolved (fixed in 2.5.4-2)
forky: resolved (fixed in 2.5.4-2)
sid: resolved (fixed in 2.5.4-2)
trixie: resolved (fixed in 2.5.4-2)
GHSA
GHSA-f3pg-chcp-5ff8: A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3
ghsa_unreviewed·2022-05-24
CVE-2021-23169 [HIGH] CWE-119 GHSA-f3pg-chcp-5ff8: A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
OSV
CVE-2021-23169: A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3
osv·2021-06-08·CVSS 8.8
CVE-2021-23169 [HIGH] CVE-2021-23169: A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1947612https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KYNJSMVA6YJY5NMKDZ5SAISKZG2KCKC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BXFLD4ZAXKAIWO6ZPBCQEEDZB5IG676K/https://security.gentoo.org/glsa/202210-31https://bugzilla.redhat.com/show_bug.cgi?id=1947612https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4KYNJSMVA6YJY5NMKDZ5SAISKZG2KCKC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BXFLD4ZAXKAIWO6ZPBCQEEDZB5IG676K/https://security.gentoo.org/glsa/202210-31
2021-06-08
Published