There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-08-25T00:00:00

Updated: 2024-08-03T17:01:07.535Z

Reserved: 2021-06-15T00:00:00

Link: CVE-2021-3605

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-25T19:15:14.757

Modified: 2023-11-07T03:38:09.340

Link: CVE-2021-3605

cve-icon Redhat

Severity : Low

Publid Date: 2021-06-11T00:00:00Z

Links: CVE-2021-3605 - Bugzilla