CVE-2021-23215

MEDIUM5.5EPSS 0.54%

openexr - security update

Published: 6/8/2021Modified: 4/28/2026
Also known as:DEBIAN-CVE-2021-23215

Description

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References (1)