Integer overflow in OpenEXR - CVE-2021-3933
Published: December 19, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow when processing files. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and perform a denial of service (DoS) attack.
Note, the vulnerability affects software installation on 32-bit systems.
Affected software
Debian Linux
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
Fedora
libIlmImf-Imf_2_1-21-32bit
libIlmImf-Imf_2_1-21-debuginfo-32bit
openexr-debugsource
openexr-debuginfo
openexr-devel
libIlmImf-Imf_2_1-21
libIlmImf-Imf_2_1-21-debuginfo
OpenEXR
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libIlmImfUtil-2_2-23
libIlmImfUtil-2_2-23-debuginfo
libIlmImf-2_2-23-debuginfo
libIlmImf-2_2-23
openexr (Debian package)
mingw-openexr
openexr
How to mitigate CVE-2021-3933
libIlmImf-Imf_2_1-21-32bit - update to 2.1.0-6.42.1
libIlmImf-Imf_2_1-21-debuginfo-32bit - update to 2.1.0-6.42.1
openexr-debugsource - addressed in versions 2.1.0-6.42.1, 2.2.1-3.38.1
openexr-debuginfo - addressed in versions 2.1.0-6.42.1, 2.2.1-3.38.1
openexr-devel - addressed in versions 2.1.0-6.42.1, 2.2.1-3.38.1
libIlmImf-Imf_2_1-21 - update to 2.1.0-6.42.1
libIlmImf-Imf_2_1-21-debuginfo - update to 2.1.0-6.42.1
OpenEXR - update to 2.1.0-6.42.1
openexr (Ubuntu package) - addressed in versions 2.2.0-11.1ubuntu1.8, 2.2.010ubuntu2.6+esm1
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-11.1ubuntu1.8, 2.2.010ubuntu2.6+esm1
libIlmImfUtil-2_2-23 - update to 2.2.1-3.38.1
libIlmImfUtil-2_2-23-debuginfo - update to 2.2.1-3.38.1
libIlmImf-2_2-23-debuginfo - update to 2.2.1-3.38.1
libIlmImf-2_2-23 - update to 2.2.1-3.38.1
openexr (Debian package) - update to 2.5.4-2+deb11u1
mingw-openexr - update to 2.5.5-4.fc34
openexr - addressed in versions 3.1.4-1.fc35, 3.1.4-1.fc36
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=2019783
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2JSMJ7HLWFPYYV7IAQZD5ZUUUN7RWBN/
- https://security.gentoo.org/glsa/202210-31
- https://www.debian.org/security/2022/dsa-5299
- https://lists.debian.org/debian-lts-announce/2022/12/msg00022.html