CVE-2021-3933
25.03.2022, 19:15
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openexr | openexr | 𝑥 < 3.1.2 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ilmbase |
| ||||||||||||||||||||||
| openexr |
| ||||||||||||||||||||||
| povray |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libIlmImf-2_2-23 |
| ||||||||||||||||||||||||||||||||||||
| libIlmImf-Imf_2_1-21 |
| ||||||||||||||||||||||||||||||||||||
| libIlmImfUtil-2_2-23 |
| ||||||||||||||||||||||||||||||||||||
| openexr |
| ||||||||||||||||||||||||||||||||||||
| openexr-devel |
|
References