Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-26945
HistoryJun 08, 2021 - 12:00 a.m.

CVE-2021-26945

2021-06-0800:00:00
ubuntu.com
ubuntu.com
13
openexr
cve-2021-26945
integer overflow
heap-buffer overflow
fuzzer
unix
exrcheck

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

22.8%

An integer overflow leading to a heap-buffer overflow was found in OpenEXR
in versions before 3.0.1. An attacker could use this flaw to crash an
application compiled with OpenEXR.

Bugs

Notes

Author Note
mdeslaur it looks like the fix for this issue actually went into the exrcheck tool used by the fuzzer

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

22.8%