Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-26260

Опубликовано: 17 мар. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR. An attacker could use this flaw to crash an application compiled with OpenEXR.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6OpenEXROut of support scope
Red Hat Enterprise Linux 7OpenEXRFix deferred
Red Hat Enterprise Linux 8gimp:flatpak/OpenEXRFix deferred
Red Hat Enterprise Linux 8OpenEXRFix deferred
Red Hat Enterprise Linux 9openexrNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-191->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1947582OpenEXR: Integer-overflow in Imf_2_5::DwaCompressor::initializeBuffers

EPSS

Процентиль: 67%
0.00541
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVSS3: 5.5
nvd
больше 4 лет назад

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVSS3: 5.5
debian
больше 4 лет назад

An integer overflow leading to a heap-buffer overflow was found in the ...

CVSS3: 5.5
github
больше 3 лет назад

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость компонента DwaCompressor программного обеспечения для хранения изображений с широкими динамическими диапазоном яркости OpenEXR, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 67%
0.00541
Низкий

5.5 Medium

CVSS3