Resource exhaustion in OpenEXR - CVE-2021-3479
Published: April 6, 2021 / Updated: May 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the Scanline API functionality. A remote attacker can use a specially crafted file, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
openEuler
cflinuxfs3
openexr-debugsource
OpenEXR-debuginfo-32bit
openexr-debuginfo
OpenEXR-32bit
OpenEXR
openexr-devel
libIlmImf-Imf_2_1-21-debuginfo-32bit
libIlmImf-Imf_2_1-21-32bit
libIlmImf-Imf_2_1-21
libIlmImf-Imf_2_1-21-debuginfo
libopenexr22 (Ubuntu package)
openexr (Ubuntu package)
OpenEXR-devel
OpenEXR-debugsource
OpenEXR-debuginfo
OpenEXR-libs
libIlmImfUtil-2_2-23-debuginfo
libIlmImfUtil-2_2-23
libIlmImf-2_2-23-debuginfo
libIlmImf-2_2-23
libopenexr24 (Ubuntu package)
libopenexr25 (Ubuntu package)
How to mitigate CVE-2021-3479
cflinuxfs3 - update to 0.234.0
openexr-debugsource - addressed in versions 1.6.1-83.17.25.1, 2.1.0-6.34.1, 2.2.1-3.27.1
OpenEXR-debuginfo-32bit - update to 1.6.1-83.17.25.1
openexr-debuginfo - addressed in versions 1.6.1-83.17.25.1, 2.1.0-6.34.1, 2.2.1-3.27.1
OpenEXR-32bit - update to 1.6.1-83.17.25.1
OpenEXR - addressed in versions 1.6.1-83.17.25.1, 2.1.0-6.34.1
openexr-devel - addressed in versions 2.1.0-6.34.1, 2.2.1-3.27.1
libIlmImf-Imf_2_1-21-debuginfo-32bit - update to 2.1.0-6.34.1
libIlmImf-Imf_2_1-21-32bit - update to 2.1.0-6.34.1
libIlmImf-Imf_2_1-21 - update to 2.1.0-6.34.1
libIlmImf-Imf_2_1-21-debuginfo - update to 2.1.0-6.34.1
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.6, 2.2.0-11.1ubuntu1.6, 2.3.0-6ubuntu0.5, 2.5.3-2ubuntu0.2
OpenEXR-devel - update to 2.2.0-19
OpenEXR-debugsource - update to 2.2.0-19
OpenEXR-debuginfo - update to 2.2.0-19
OpenEXR-libs - update to 2.2.0-19
OpenEXR - update to 2.2.0-19
libIlmImfUtil-2_2-23-debuginfo - update to 2.2.1-3.27.1
libIlmImfUtil-2_2-23 - update to 2.2.1-3.27.1
libIlmImf-2_2-23-debuginfo - update to 2.2.1-3.27.1
libIlmImf-2_2-23 - update to 2.2.1-3.27.1
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.5
libopenexr25 (Ubuntu package) - update to 2.5.3-2ubuntu0.2