CVE-2021-20298

HIGH

Openexr < 2.5.7 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 47.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400 CWE-787
Status published
Products (2)
debian/debian_linux 10.0
openexr/openexr < 2.5.7
Published Aug 23, 2022
Tracked Since Feb 18, 2026