Your submission was sent successfully! Close

CVE-2021-3605

Published: 17 June 2021

There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.

Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
openexr
Launchpad, Ubuntu, Debian
bionic
Released (2.2.0-11.1ubuntu1.7)
focal Needs triage

groovy Ignored
(reached end-of-life)
hirsute Ignored
(reached end-of-life)
impish Needed

jammy Not vulnerable
(2.5.7-1)
trusty Does not exist

upstream
Released (2.5.7-1)
xenial
Released (2.2.0-10ubuntu2.6+esm1)