Your submission was sent successfully! Close

CVE-2021-20296

Published: 1 April 2021

A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

Priority

Low

CVSS 3 base score: 5.3

Status

Package Release Status
openexr
Launchpad, Ubuntu, Debian
bionic
Released (2.2.0-11.1ubuntu1.7)
focal Needed

groovy Ignored
(reached end-of-life)
hirsute Not vulnerable
(2.5.4-1)
impish Not vulnerable
(2.5.4-2)
jammy Not vulnerable
(2.5.7-1)
precise Does not exist

trusty Does not exist

upstream
Released (2.5.4-1)
xenial
Released (2.2.0-10ubuntu2.6+esm1)