CVE-2021-20298

HIGH

OpenEXR < 2.5.7 - Denial of Service via B44Compressor Memory Exhaustion

Title source: llm
STIX 2.1

Description

A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 7.5
EPSS 0.0122
EPSS Percentile 65.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400 CWE-787
Status published
Products (2)
debian/debian_linux 10.0
openexr/openexr < 2.5.7
Published Aug 23, 2022
Tracked Since Feb 18, 2026