Out-of-bounds read in OpenEXR - CVE-2021-3477
Published: April 6, 2021 / Updated: May 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the deep tile sample size calculations. A remote attacker can create a specially crafted file, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Gentoo Linux
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
openEuler
cflinuxfs3
libIlmImf-Imf_2_1-21-debuginfo-32bit
libIlmImf-Imf_2_1-21-32bit
openexr-debugsource
openexr-debuginfo
openexr-devel
libIlmImf-Imf_2_1-21
libIlmImf-Imf_2_1-21-debuginfo
OpenEXR
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
OpenEXR-libs
OpenEXR-debuginfo
OpenEXR-devel
OpenEXR-debugsource
libIlmImfUtil-2_2-23-debuginfo
libIlmImfUtil-2_2-23
libIlmImf-2_2-23-debuginfo
libIlmImf-2_2-23
libopenexr24 (Ubuntu package)
libopenexr25 (Ubuntu package)
How to mitigate CVE-2021-3477
cflinuxfs3 - update to 0.234.0
libIlmImf-Imf_2_1-21-debuginfo-32bit - update to 2.1.0-6.42.1
libIlmImf-Imf_2_1-21-32bit - update to 2.1.0-6.42.1
openexr-debugsource - addressed in versions 2.1.0-6.42.1, 2.2.1-3.27.1
openexr-debuginfo - addressed in versions 2.1.0-6.42.1, 2.2.1-3.27.1
openexr-devel - addressed in versions 2.1.0-6.42.1, 2.2.1-3.27.1
libIlmImf-Imf_2_1-21 - update to 2.1.0-6.42.1
libIlmImf-Imf_2_1-21-debuginfo - update to 2.1.0-6.42.1
OpenEXR - update to 2.1.0-6.42.1
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6, 2.3.0-6ubuntu0.5, 2.5.3-2ubuntu0.2
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6
OpenEXR - update to 2.2.0-19
OpenEXR-libs - update to 2.2.0-19
OpenEXR-debuginfo - update to 2.2.0-19
OpenEXR-devel - update to 2.2.0-19
OpenEXR-debugsource - update to 2.2.0-19
libIlmImfUtil-2_2-23-debuginfo - update to 2.2.1-3.27.1
libIlmImfUtil-2_2-23 - update to 2.2.1-3.27.1
libIlmImf-2_2-23-debuginfo - update to 2.2.1-3.27.1
libIlmImf-2_2-23 - update to 2.2.1-3.27.1
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.5
libopenexr25 (Ubuntu package) - update to 2.5.3-2ubuntu0.2