Resource exhaustion in OpenEXR - CVE-2021-3479

 

Resource exhaustion in OpenEXR - CVE-2021-3479

Published: April 6, 2021 / Updated: May 18, 2021


Vulnerability identifier: #VU51934
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3479
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the Scanline API functionality. A remote attacker can use a specially crafted file, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

OpenEXR
Gentoo Linux
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
openEuler
cflinuxfs3
openexr-debugsource
OpenEXR-debuginfo-32bit
openexr-debuginfo
OpenEXR-32bit
OpenEXR
openexr-devel
libIlmImf-Imf_2_1-21-debuginfo-32bit
libIlmImf-Imf_2_1-21-32bit
libIlmImf-Imf_2_1-21
libIlmImf-Imf_2_1-21-debuginfo
libopenexr22 (Ubuntu package)
openexr (Ubuntu package)
OpenEXR-devel
OpenEXR-debugsource
OpenEXR-debuginfo
OpenEXR-libs
libIlmImfUtil-2_2-23-debuginfo
libIlmImfUtil-2_2-23
libIlmImf-2_2-23-debuginfo
libIlmImf-2_2-23
libopenexr24 (Ubuntu package)
libopenexr25 (Ubuntu package)

How to mitigate CVE-2021-3479

Install updates from vendor's website.

OpenEXR - addressed in versions 2.4.3, 3.0.0 beta
cflinuxfs3 - update to 0.234.0
openexr-debugsource - addressed in versions 1.6.1-83.17.25.1, 2.1.0-6.34.1, 2.2.1-3.27.1
OpenEXR-debuginfo-32bit - update to 1.6.1-83.17.25.1
openexr-debuginfo - addressed in versions 1.6.1-83.17.25.1, 2.1.0-6.34.1, 2.2.1-3.27.1
OpenEXR-32bit - update to 1.6.1-83.17.25.1
OpenEXR - addressed in versions 1.6.1-83.17.25.1, 2.1.0-6.34.1
openexr-devel - addressed in versions 2.1.0-6.34.1, 2.2.1-3.27.1
libIlmImf-Imf_2_1-21-debuginfo-32bit - update to 2.1.0-6.34.1
libIlmImf-Imf_2_1-21-32bit - update to 2.1.0-6.34.1
libIlmImf-Imf_2_1-21 - update to 2.1.0-6.34.1
libIlmImf-Imf_2_1-21-debuginfo - update to 2.1.0-6.34.1
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6, 2.3.0-6ubuntu0.5, 2.5.3-2ubuntu0.2
OpenEXR-devel - update to 2.2.0-19
OpenEXR-debugsource - update to 2.2.0-19
OpenEXR-debuginfo - update to 2.2.0-19
OpenEXR-libs - update to 2.2.0-19
OpenEXR - update to 2.2.0-19
libIlmImfUtil-2_2-23-debuginfo - update to 2.2.1-3.27.1
libIlmImfUtil-2_2-23 - update to 2.2.1-3.27.1
libIlmImf-2_2-23-debuginfo - update to 2.2.1-3.27.1
libIlmImf-2_2-23 - update to 2.2.1-3.27.1
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.5
libopenexr25 (Ubuntu package) - update to 2.5.3-2ubuntu0.2

External References

Related Security Bulletins