6.5
CVSSv3

CVE-2021-3941

Published: 25/03/2022 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked with OpenEXR.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openexr openexr 3.1.2

redhat enterprise linux 7.0

redhat enterprise linux 6.0

redhat enterprise linux 8.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1014828 openexr: CVE-2021-3933 CVE-2021-3941 CVE-2021-45942 Package: src:openexr; Maintainer for src:openexr is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 12 Jul 2022 19:33:02 UTC Severity: grave T ...
Multiple security vulnerabilities have been found in OpenEXR, command-line tools and a library for the OpenEXR image format Buffer overflows or out-of-bound reads could lead to a denial of service (application crash) if a malformed image file is processed For the stable distribution (bullseye), these problems have been fixed in version 254-2+de ...
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t is less than 64 bits This issue could cause an invalid bytesPerLine and maxBytesPerLine value, which leads to problems with application stability or other attack paths (CVE-2021-3933) In ImfChromaticitiescpp routine RGBtoXYZ(), there are some division o ...
ALAS-2022-216 Amazon Linux 2022 Security Advisory: ALAS-2022-216 Advisory Release Date: 2022-12-06 16:41 Pacific ...