A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 4, 2022 |
| Suse | — | Upgrade libIlmImf-2_2-23Upgrade libIlmImf-Imf_2_1-21Upgrade libilmimfutil-2_2-23-32bitUpgrade OpenEXR-develUpgrade openexrUpgrade libilmimf-2_2-23-32bitUpgrade libIlmImfUtil-2_2-23Upgrade openexr-docUpgrade libIlmImf-Imf_2_1-21-32bit | Aug 21, 2021 | Aug 20, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub