CVE-2021-3933
published 2022-03-25CVE-2021-3933: An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and…
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.85%
54.0th percentile
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openexr | < openexr 3.1.5-2 (bookworm) | openexr 3.1.5-2 (bookworm) |
| fedoraproject | fedora | — | — |
| openexr | openexr | < 3.1.2 | 3.1.2 |
| openexr | openexr | — | — |
| openexr | openexr | >= 0 < 2.5.4-2+deb11u1 | 2.5.4-2+deb11u1 |
| openexr | openexr | >= 0 < 3.1.5-2 | 3.1.5-2 |
| openexr | openexr | >= 0 < 3.1.5-2 | 3.1.5-2 |
| openexr | openexr | >= 0 < 3.1.5-2 | 3.1.5-2 |
| openexr | openexr | >= 0 < 2.3.0-6ubuntu0.5+esm1 | 2.3.0-6ubuntu0.5+esm1 |
| openexr | openexr | >= 0 < 2.5.7-1ubuntu0.1~esm1 | 2.5.7-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenEXR vulnerabilities
vendor_ubuntu·2022-09-20·CVSS 5.3
CVE-2021-23215 [MEDIUM] OpenEXR vulnerabilities
Title: OpenEXR vulnerabilities
Summary: Several security issues were fixed in OpenEXR.
It was discovered that OpenEXR incorrectly handled certain malformed EXR
image files. If a user were tricked into opening a crafted EXR image file,
a remote attacker could cause a denial of service, or possibly execute
arbitrary code. These issues only affected Ubuntu 20.04 ESM. (CVE-2021-3598,
CVE-2021-3605, CVE-2021-20296, CVE-2021-23215, CVE-2021-26260)
It was discovered that OpenEXR incorrectly handled certain EXR
image files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code. (CVE-2021-3933)
It was discovered that OpenEXR incorrectly handled certain EXR image files.
An attacker could possibly use this issue to cause a crash. (CVE-2021-3941)
Instructions: In ge
Ubuntu
OpenEXR vulnerability
vendor_ubuntu·2021-11-11
CVE-2021-3933 OpenEXR vulnerability
Title: OpenEXR vulnerability
Summary: OpenEXR could be made to crash or execute arbitrary code if it received a specially
crafted EXR file.
It was discovered that OpenEXR incorrectly handled certain EXR
image files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openexr: Integer-overflow in Imf_3_1::bytesPerDeepLineTable
vendor_redhat·2021-09-18·CVSS 5.5
CVE-2021-3933 [MEDIUM] CWE-190 openexr: Integer-overflow in Imf_3_1::bytesPerDeepLineTable
openexr: Integer-overflow in Imf_3_1::bytesPerDeepLineTable
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t is less than 64 bits. This issue could cause an invalid bytesPerLine and maxBytesPerLine value, which leads to problems with application stability or other attack paths.
Statement: Product-specific severity for Red Hat Enterprise Linux 7 and 8 was set to Low because 32-bit system versions are not shipped or supported. The flaw is out of support scope for Red Hat Enterprise Linux 6
Debian
CVE-2021-3933: openexr - An integer overflow could occur when OpenEXR processes a crafted file on systems...
vendor_debian·2021·CVSS 5.5
CVE-2021-3933 [MEDIUM] CVE-2021-3933: openexr - An integer overflow could occur when OpenEXR processes a crafted file on systems...
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
Scope: local
bookworm: resolved (fixed in 3.1.5-2)
bullseye: resolved (fixed in 2.5.4-2+deb11u1)
forky: resolved (fixed in 3.1.5-2)
sid: resolved (fixed in 3.1.5-2)
trixie: resolved (fixed in 3.1.5-2)
OSV
openexr vulnerabilities
osv·2022-09-20·CVSS 5.3
CVE-2021-3598 [MEDIUM] openexr vulnerabilities
openexr vulnerabilities
It was discovered that OpenEXR incorrectly handled certain malformed EXR
image files. If a user were tricked into opening a crafted EXR image file,
a remote attacker could cause a denial of service, or possibly execute
arbitrary code. These issues only affected Ubuntu 20.04 ESM. (CVE-2021-3598,
CVE-2021-3605, CVE-2021-20296, CVE-2021-23215, CVE-2021-26260)
It was discovered that OpenEXR incorrectly handled certain EXR
image files. An attacker could possibly use this issue to cause a crash
or execute arbitrary code. (CVE-2021-3933)
It was discovered that OpenEXR incorrectly handled certain EXR image files.
An attacker could possibly use this issue to cause a crash. (CVE-2021-3941)
GHSA
GHSA-jmmx-24xf-r6qm: An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits
ghsa_unreviewed·2022-03-26
CVE-2021-3933 [MEDIUM] CWE-190 GHSA-jmmx-24xf-r6qm: An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
OSV
CVE-2021-3933: An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits
osv·2022-03-25·CVSS 5.5
CVE-2021-3933 [MEDIUM] CVE-2021-3933: An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2019783https://lists.debian.org/debian-lts-announce/2022/12/msg00022.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I2JSMJ7HLWFPYYV7IAQZD5ZUUUN7RWBN/https://security.gentoo.org/glsa/202210-31https://www.debian.org/security/2022/dsa-5299https://bugzilla.redhat.com/show_bug.cgi?id=2019783https://lists.debian.org/debian-lts-announce/2022/12/msg00022.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I2JSMJ7HLWFPYYV7IAQZD5ZUUUN7RWBN/https://security.gentoo.org/glsa/202210-31https://www.debian.org/security/2022/dsa-5299
2022-03-25
Published