Related Vulnerabilities: CVE-2021-3605  

A heap-buffer overflow was found in the rleUncompress function of OpenEXR. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.

Severity Medium

Remote Yes

Type Arbitrary code execution

Description

A heap-buffer overflow was found in the rleUncompress function of OpenEXR. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.

AVG-2071 openexr 3.0.4-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1970991
https://github.com/AcademySoftwareFoundation/openexr/pull/1036
https://github.com/AcademySoftwareFoundation/openexr/commit/25259a84827234a283f6f9db72978198c7a3f268