Lucene search

K
osvGoogleOSV:CVE-2021-3478
HistoryMar 31, 2021 - 2:15 p.m.

CVE-2021-3478

2021-03-3114:15:21
Google
osv.dev
13
openexr
scanline
input file
memory consumption
system availability
vulnerability
cve-2021-3478
crafted file
system software

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

37.8%

There’s a flaw in OpenEXR’s scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availability.