Lucene search

K
osvGoogleOSV:CVE-2021-3479
HistoryMar 31, 2021 - 2:15 p.m.

CVE-2021-3479

2021-03-3114:15:21
Google
osv.dev
9
openexr
vulnerability
memory consumption
system impact

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

37.8%

There’s a flaw in OpenEXR’s Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availability.