Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-26260

Опубликовано: 08 июн. 2021
Источник: debian

Описание

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openexrfixed2.5.7-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1947582

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29423

  • https://github.com/AcademySoftwareFoundation/openexr/pull/894

  • https://github.com/AcademySoftwareFoundation/openexr/commit/088a61434568cedf3ac1521c44584be397909078 (v3.0.0-beta)

  • https://github.com/AcademySoftwareFoundation/openexr/commit/4212416433a230334cef0ac122cb8d722746035d (2.5)

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVSS3: 5.5
redhat
почти 5 лет назад

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVSS3: 5.5
nvd
больше 4 лет назад

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVSS3: 5.5
github
больше 3 лет назад

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость компонента DwaCompressor программного обеспечения для хранения изображений с широкими динамическими диапазоном яркости OpenEXR, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании