Integer overflow in OpenEXR - CVE-2021-3475

 

Integer overflow in OpenEXR - CVE-2021-3475

Published: April 6, 2021 / Updated: May 18, 2021


Vulnerability identifier: #VU51931
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3475
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) on the target system.

The vulnerability exists due to integer overflow. A remote attacker can pass specially crafted file, trigger integer overflow and cause a denial of service condition on the target system.


Affected software

OpenEXR
Gentoo Linux
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
openEuler
cflinuxfs3
libopenexr22 (Ubuntu package)
openexr (Ubuntu package)
OpenEXR-debugsource
OpenEXR-devel
OpenEXR-debuginfo
OpenEXR-libs
OpenEXR
libIlmImf-2_2-23
openexr-devel
openexr-debugsource
openexr-debuginfo
libIlmImfUtil-2_2-23-debuginfo
libIlmImfUtil-2_2-23
libIlmImf-2_2-23-debuginfo
libopenexr24 (Ubuntu package)
libopenexr25 (Ubuntu package)

How to mitigate CVE-2021-3475

Install updates from vendor's website.

OpenEXR - addressed in versions 2.4.3, 3.0.0 beta
cflinuxfs3 - update to 0.234.0
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6, 2.3.0-6ubuntu0.5, 2.5.3-2ubuntu0.2
OpenEXR-debugsource - update to 2.2.0-19
OpenEXR-devel - update to 2.2.0-19
OpenEXR-debuginfo - update to 2.2.0-19
OpenEXR-libs - update to 2.2.0-19
OpenEXR - update to 2.2.0-19
libIlmImf-2_2-23 - update to 2.2.1-3.24.1
openexr-devel - update to 2.2.1-3.24.1
openexr-debugsource - update to 2.2.1-3.24.1
openexr-debuginfo - update to 2.2.1-3.24.1
libIlmImfUtil-2_2-23-debuginfo - update to 2.2.1-3.24.1
libIlmImfUtil-2_2-23 - update to 2.2.1-3.24.1
libIlmImf-2_2-23-debuginfo - update to 2.2.1-3.24.1
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.5
libopenexr25 (Ubuntu package) - update to 2.5.3-2ubuntu0.2

External References

Related Security Bulletins