Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6vh-h3m7-7676

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.

EPSS

Процентиль: 70%
0.00654
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.

CVSS3: 5.3
redhat
почти 5 лет назад

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.

CVSS3: 5.3
nvd
почти 5 лет назад

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.

CVSS3: 5.3
debian
почти 5 лет назад

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker ...

CVSS3: 5.3
fstec
больше 5 лет назад

Уязвимость функции calculateNumTiles()(OpenEXR/IlmImf/ImfTiledMisc.cpp) библиотеки OpenEXR, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 70%
0.00654
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-190