Your submission was sent successfully! Close

CVE-2021-20299

Published: 16 March 2022

A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

Priority

Negligible

CVSS 3 base score: 7.5

Status

Package Release Status
openexr
Launchpad, Ubuntu, Debian
bionic Needed

focal Needs triage

groovy Ignored
(reached end-of-life)
hirsute Not vulnerable
(2.5.4-1)
impish Not vulnerable
(2.5.4-2)
jammy Not vulnerable
(2.5.7-1)
trusty Does not exist

upstream
Released (2.5.4-1)
xenial Needs triage