ZeroHour

CVE-2021-23215

CVSS 3.1
5.5 medium
EPSS
1%p65
Published
()
Modified
Description

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

Vendors
openexrfedoraprojectdebian
Products
openexr, fedora, debian linux
Weakness
CWE-400, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.