CVE-2021-3474 - log back

CVE-2021-3474 edited at 31 Mar 2021 08:50:45
Description
- There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
+ There's a flaw in OpenEXR in versions before 2.5.4. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
References
https://bugzilla.redhat.com/show_bug.cgi?id=1939142
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24831
+ https://github.com/AcademySoftwareFoundation/openexr/pull/818
https://github.com/AcademySoftwareFoundation/openexr/commit/c3ed4a1db1f39bf4524a644cb2af81dc8cfab33f
+ https://github.com/AcademySoftwareFoundation/openexr/commit/0c2b46f630a3b5f2f561c2849d047ee39f899179
CVE-2021-3474 edited at 31 Mar 2021 07:30:02
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1939145
+ https://bugzilla.redhat.com/show_bug.cgi?id=1939142
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24787
+ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24831
- https://github.com/AcademySoftwareFoundation/openexr/commit/eec0dba242bedd2778c973ae4af112107b33d9c9
+ https://github.com/AcademySoftwareFoundation/openexr/commit/c3ed4a1db1f39bf4524a644cb2af81dc8cfab33f
CVE-2021-3474 edited at 31 Mar 2021 07:28:04
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Denial of service
Description
+ There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1939145
+ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24787
+ https://github.com/AcademySoftwareFoundation/openexr/commit/eec0dba242bedd2778c973ae4af112107b33d9c9
Notes
CVE-2021-3474 created at 31 Mar 2021 07:26:43