CVE-2021-3477

Out-of-bounds Read in conan/openexr

Identifiers

CVE-2021-3477

Package Slug

conan/openexr

Vulnerability

Out-of-bounds Read

Description

There's a flaw in OpenEXR's deep tile sample size calculations . An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read. The greatest risk of this flaw is to application availability.

Affected Versions

All versions before 2.4.3, all versions starting from 2.5.0 before 2.5.4

Solution

Upgrade to version 2.5.4 or above.

Last Modified

2021-04-06

source