CVE-2021-20296
—CVSS 3.1
5.3 medium
EPSS
2%p76
Published
()
Modified
Description
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
In the news0 stories
No ingested article mentions this CVE yet.