OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light & Magic for use in computer imaging applications.
Security Fix(es):
A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.(CVE-2021-20300)
A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.(CVE-2021-20302)
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.(CVE-2021-3933)
{ "severity": "Medium" }
{ "src": [ "OpenEXR-2.2.0-26.oe1.src.rpm" ], "aarch64": [ "OpenEXR-libs-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-devel-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-debugsource-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-debuginfo-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-2.2.0-26.oe1.aarch64.rpm" ], "x86_64": [ "OpenEXR-debuginfo-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-libs-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-devel-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-debugsource-2.2.0-26.oe1.x86_64.rpm" ] }
{ "src": [ "OpenEXR-2.2.0-26.oe1.src.rpm" ], "aarch64": [ "OpenEXR-libs-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-debuginfo-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-debugsource-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-devel-2.2.0-26.oe1.aarch64.rpm", "OpenEXR-2.2.0-26.oe1.aarch64.rpm" ], "x86_64": [ "OpenEXR-debugsource-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-debuginfo-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-libs-2.2.0-26.oe1.x86_64.rpm", "OpenEXR-devel-2.2.0-26.oe1.x86_64.rpm" ] }