A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 4, 2022 |
| Suse | — | Upgrade libIlmImf-2_2-23Upgrade libilmimf-2_2-23-32bitUpgrade openexr-docUpgrade OpenEXR-develUpgrade libIlmImf-Imf_2_1-21Upgrade libIlmImfUtil-2_2-23Upgrade OpenEXR-32bitUpgrade libilmimfutil-2_2-23-32bitUpgrade libIlmImf-Imf_2_1-21-32bitUpgrade openexr | Aug 21, 2021 | Aug 20, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub