There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade OpenEXRUpgrade OpenEXR-libsUpgrade OpenEXR-debuginfoUpgrade OpenEXR-devel | Jun 8, 2023 | Aug 25, 2021 |
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Oct 31, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp3 | — | — | May 25, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp5 | — | — | Apr 26, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Aug 25, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2021 |
| Suse | — | Upgrade libilmimf-imf_2_1-21-32bitUpgrade openexrUpgrade libilmimfutil-2_2-23-32bitUpgrade libilmimf-2_2-23Upgrade libilmimfutil-2_2-23Upgrade openexr-develUpgrade libilmimf-imf_2_1-21Upgrade libilmimf-2_2-23-32bitUpgrade openexr-docUpgrade openexr-32bit | Jun 23, 2021 | Jun 22, 2021 |
| Ubuntu | — | Upgrade libopenexr24 (Ubuntu Pro)Upgrade openexrUpgrade openexr (Ubuntu Pro)Upgrade libopenexr22Upgrade libopenexr22 (Ubuntu Pro)Upgrade libopenexr25 (Ubuntu Pro) | Jun 23, 2021 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub