5.5
CVSSv3

CVE-2021-26260

Published: 08/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions prior to 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openexr openexr

fedoraproject fedora 33

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #992703 openexr: CVE-2021-26260 Package: src:openexr; Maintainer for src:openexr is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 22 Aug 2021 15:03:01 UTC Severity: important Tags: security, upstr ...
Multiple security vulnerabilities have been found in OpenEXR, command-line tools and a library for the OpenEXR image format Buffer overflows or out-of-bound reads could lead to a denial of service (application crash) if a malformed image file is processed For the stable distribution (bullseye), these problems have been fixed in version 254-2+de ...