There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Aug 22, 2024 | Jul 6, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 6, 2021 |
| Debian | — | Upgrade openexr | Jul 5, 2021 | Jul 5, 2021 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Oct 31, 2022 | Jul 6, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Jul 6, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 6, 2021 |
| Suse | — | Upgrade libIlmImfUtil-2_2-23Upgrade libilmimf-2_2-23-32bitUpgrade openexr-docUpgrade libIlmImf-Imf_2_1-21-32bitUpgrade libIlmImf-Imf_2_1-21Upgrade openexrUpgrade libilmimfutil-2_2-23-32bitUpgrade libIlmImf-2_2-23Upgrade OpenEXR-devel | Jun 25, 2021 | Jun 22, 2021 |
| Ubuntu | — | Upgrade libopenexr25 (Ubuntu Pro)Upgrade openexrUpgrade libopenexr22Upgrade openexr (Ubuntu Pro)Upgrade libopenexr22 (Ubuntu Pro)Upgrade libopenexr24 (Ubuntu Pro) | Jun 23, 2021 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub