Resource exhaustion in OpenEXR - CVE-2021-3478
Published: April 6, 2021 / Updated: May 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the scanline input file functionality. A remote attacker can use a specially crafted file, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Ubuntu
cflinuxfs3
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libopenexr24 (Ubuntu package)
libopenexr25 (Ubuntu package)
How to mitigate CVE-2021-3478
cflinuxfs3 - update to 0.234.0
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6, 2.3.0-6ubuntu0.5, 2.5.3-2ubuntu0.2
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.5
libopenexr25 (Ubuntu package) - update to 2.5.3-2ubuntu0.2