There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade OpenEXR-debuginfoUpgrade OpenEXR-develUpgrade OpenEXRUpgrade OpenEXR-libs | Jun 8, 2023 | Aug 25, 2021 |
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Oct 31, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp3 | — | — | May 25, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp5 | — | — | Apr 26, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Aug 25, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2021 |
| Suse | — | Upgrade libilmimf-imf_2_1-21-32bitUpgrade libilmimfutil-2_2-23Upgrade openexr-develUpgrade openexrUpgrade libilmimf-imf_2_1-21Upgrade libilmimfutil-2_2-23-32bitUpgrade libilmimf-2_2-23Upgrade openexr-docUpgrade libilmimf-2_2-23-32bitUpgrade openexr-32bit | Jun 23, 2021 | Jun 22, 2021 |
| Ubuntu | — | Upgrade libopenexr24 (Ubuntu Pro)Upgrade libopenexr22 (Ubuntu Pro)Upgrade openexr (Ubuntu Pro)Upgrade libopenexr22Upgrade libopenexr25 (Ubuntu Pro)Upgrade openexr | Jun 23, 2021 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub