There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.
{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libopenexr-dev",
            "binary_version": "2.2.0-10ubuntu2.6"
        },
        {
            "binary_name": "libopenexr22",
            "binary_version": "2.2.0-10ubuntu2.6"
        },
        {
            "binary_name": "openexr",
            "binary_version": "2.2.0-10ubuntu2.6"
        }
    ]
}
          {
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libopenexr-dev",
            "binary_version": "2.2.0-11.1ubuntu1.6"
        },
        {
            "binary_name": "libopenexr22",
            "binary_version": "2.2.0-11.1ubuntu1.6"
        },
        {
            "binary_name": "openexr",
            "binary_version": "2.2.0-11.1ubuntu1.6"
        }
    ]
}