There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade OpenEXR-develUpgrade OpenEXR-debuginfoUpgrade OpenEXRUpgrade OpenEXR-libs | Jun 8, 2023 | Aug 25, 2021 |
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Oct 31, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp3 | — | — | May 25, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp5 | — | — | Apr 26, 2022 | Aug 25, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Aug 25, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2021 |
| Suse | — | Upgrade libIlmImf-2_2-23Upgrade OpenEXR-32bitUpgrade openexrUpgrade libilmimfutil-2_2-23-32bitUpgrade OpenEXR-develUpgrade libIlmImf-Imf_2_1-21Upgrade libilmimf-2_2-23-32bitUpgrade libIlmImfUtil-2_2-23Upgrade libIlmImf-Imf_2_1-21-32bitUpgrade openexr-doc | Jun 23, 2021 | Jun 22, 2021 |
| Ubuntu | — | Upgrade libopenexr24 (Ubuntu Pro)Upgrade openexrUpgrade libopenexr22 (Ubuntu Pro)Upgrade openexr (Ubuntu Pro)Upgrade libopenexr25 (Ubuntu Pro)Upgrade libopenexr22 | Jun 23, 2021 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub