Related Vulnerabilities: CVE-2021-3598  

A heap-buffer overflow was found in the readChars function of OpenEXR. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.

Severity Medium

Remote Yes

Type Arbitrary code execution

Description

A heap-buffer overflow was found in the readChars function of OpenEXR. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.

AVG-2071 openexr 3.0.4-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1970987
https://github.com/AcademySoftwareFoundation/openexr/issues/1033
https://github.com/AcademySoftwareFoundation/openexr/pull/1037
https://github.com/AcademySoftwareFoundation/openexr/commit/566f5241edd87445373885d5f7a904dc81e866c1