Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-20298
HistoryAug 23, 2022 - 12:00 a.m.

CVE-2021-20298

2022-08-2300:00:00
ubuntu.com
ubuntu.com
21
openexr
b44compressor
memory exhaustion
crafted file
system availability
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

61.9%

A flaw was found in OpenEXR’s B44Compressor. This flaw allows an attacker
who can submit a crafted file to be processed by OpenEXR, to exhaust all
memory accessible to the application. The highest threat from this
vulnerability is to system availability.

Bugs

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

61.9%