A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.
[
{
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/academysoftwarefoundation/openexr/commit/85fd638ae0d5fa132434f4cbf32590261c1dba97",
"target": {
"file": "OpenEXR/IlmImf/ImfB44Compressor.cpp"
},
"id": "CVE-2021-20298-7d322475",
"signature_version": "v1",
"digest": {
"line_hashes": [
"337182622941885860691948893909499588135",
"323662791025237067706865570695215691721",
"262227886135352975191095936665666742560",
"102441096919337918920502902234704070284"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/academysoftwarefoundation/openexr/commit/85fd638ae0d5fa132434f4cbf32590261c1dba97",
"target": {
"function": "B44Compressor::B44Compressor",
"file": "OpenEXR/IlmImf/ImfB44Compressor.cpp"
},
"id": "CVE-2021-20298-a5a84c0a",
"signature_version": "v1",
"digest": {
"length": 1483.0,
"function_hash": "73840588326705174605545363839552404531"
}
}
]