A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
[
{
"signature_version": "v1",
"id": "CVE-2021-20296-3b14fd36",
"source": "https://github.com/openexr/openexr/commit/7bab6d44caf65ee3cabe31553f8e2968c8747be5",
"digest": {
"length": 1690.0,
"function_hash": "147499493693564905582259429661292444797"
},
"deprecated": false,
"target": {
"function": "ScanLineInputFile::initialize",
"file": "OpenEXR/IlmImf/ImfScanLineInputFile.cpp"
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"id": "CVE-2021-20296-bea1d206",
"source": "https://github.com/openexr/openexr/commit/7bab6d44caf65ee3cabe31553f8e2968c8747be5",
"digest": {
"line_hashes": [
"183799983013183831380237481661086301550",
"111519733374137260985206676436366582935",
"338562742485568351177658719788975857619",
"84570287594119879542064273017314287589",
"152453817114836365619507449973532304004",
"152126518450649847430180110668365421093",
"334371091860315902789981231789629231501"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "OpenEXR/IlmImf/ImfScanLineInputFile.cpp"
},
"signature_type": "Line"
}
]