ZeroHour

CVE-2021-3933

CVSS 3.1
5.5 medium
EPSS
<1%p57
Published
()
Modified
Description

An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.

Vendors
openexrfedoraprojectdebian
Products
openexr, fedora, debian linux
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.