CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
Percentile
30.2%
Severity: Medium
Date : 2021-07-06
CVE-ID : CVE-2021-3598
Package : openexr
Type : arbitrary code execution
Remote : Yes
Link : https://security.archlinux.org/AVG-2071
The package openexr before version 3.0.5-1 is vulnerable to arbitrary
code execution.
Upgrade to 3.0.5-1.
The problem has been fixed upstream in version 3.0.5.
None.
A heap-buffer overflow was found in the readChars function of OpenEXR
before version 3.0.5. An attacker could use this flaw to execute
arbitrary code with the permissions of the user running the application
compiled against OpenEXR.
An attacker could execute arbitrary code through a crafted EXR image
file.
https://bugzilla.redhat.com/show_bug.cgi?id=1970987
https://github.com/AcademySoftwareFoundation/openexr/issues/1033
https://github.com/AcademySoftwareFoundation/openexr/pull/1037
https://github.com/AcademySoftwareFoundation/openexr/commit/b054116e57ebf62739a17217f922359b174d1332
https://security.archlinux.org/CVE-2021-3598
bugzilla.redhat.com/show_bug.cgi?id=1970987
github.com/AcademySoftwareFoundation/openexr/commit/b054116e57ebf62739a17217f922359b174d1332
github.com/AcademySoftwareFoundation/openexr/issues/1033
github.com/AcademySoftwareFoundation/openexr/pull/1037
security.archlinux.org/AVG-2071
security.archlinux.org/CVE-2021-3598
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
Percentile
30.2%