Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2021-20303

Published: 4 March 2022

A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.

Priority

Low

Cvss 3 Severity Score

6.1

Score breakdown

Status

Package Release Status
openexr
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needs triage

groovy Ignored
(end of life)
hirsute Not vulnerable
(2.5.4-1)
impish Not vulnerable
(2.5.4-2)
jammy Not vulnerable
(2.5.7-1)
kinetic Not vulnerable
(2.5.7-1)
lunar Not vulnerable
(2.5.7-1)
mantic Not vulnerable
(2.5.7-1)
trusty Does not exist

upstream
Released (2.5.4-1)
xenial Needs triage

Patches:
upstream: https://github.com/AcademySoftwareFoundation/openexr/pull/831/commits/901059f541acf3013efbbb819035f4a01de8d43e
upstream: https://github.com/AcademySoftwareFoundation/openexr/pull/831/commits/a03aafb6bb1cd29a6cbd8d7e6434ad4c2b23b935

Severity score breakdown

Parameter Value
Base score 6.1
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact Low
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H