There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Aug 22, 2024 | Mar 30, 2021 |
| Debian | — | Upgrade openexr | Jul 5, 2021 | Mar 30, 2021 |
| Freebsd | — | Upgrade ilmbaseUpgrade openexr | Nov 4, 2022 | Feb 12, 2021 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Jul 12, 2021 | Mar 30, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Mar 30, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 30, 2021 |
| Suse | — | Upgrade openexrUpgrade libIlmImf-2_2-23Upgrade OpenEXR-develUpgrade libilmimfutil-2_2-23-32bitUpgrade libilmimf-2_2-23-32bitUpgrade openexr-docUpgrade libIlmImfUtil-2_2-23 | Apr 13, 2021 | Mar 30, 2021 |
| Ubuntu | — | Upgrade libopenexr25Upgrade libopenexr22Upgrade libopenexr24Upgrade openexr | Apr 2, 2021 | Mar 30, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub