UBUNTU-CVE-2021-3598
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3598
UBUNTU-CVE-2021-3598
Summary:
Details: There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
References: https://ubuntu.com/security/CVE-2021-3598, https://github.com/AcademySoftwareFoundation/openexr/pull/1037, https://ubuntu.com/security/notices/USN-4996-1, https://ubuntu.com/security/notices/USN-4996-2, https://ubuntu.com/security/notices/USN-5620-1, https://www.cve.org/CVERecord?id=CVE-2021-3598
Affected packages
Package
Name: openexr
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
