CVE-2021-3476 - log back

CVE-2021-3476 edited at 31 Mar 2021 08:52:10
Description
- A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
+ A flaw was found in OpenEXR's B44 uncompression functionality in versions before 2.5.4. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
References
https://bugzilla.redhat.com/show_bug.cgi?id=1939145
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24787
+ https://github.com/AcademySoftwareFoundation/openexr/pull/832
https://github.com/AcademySoftwareFoundation/openexr/commit/eec0dba242bedd2778c973ae4af112107b33d9c9
+ https://github.com/AcademySoftwareFoundation/openexr/commit/0c2b46f630a3b5f2f561c2849d047ee39f899179
CVE-2021-3476 edited at 31 Mar 2021 07:31:50
Description
- There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
+ A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.
References
https://bugzilla.redhat.com/show_bug.cgi?id=1939145
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24787
https://github.com/AcademySoftwareFoundation/openexr/commit/eec0dba242bedd2778c973ae4af112107b33d9c9
Notes
CVE-2021-3476 edited at 31 Mar 2021 07:29:12
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Denial of service
Description
+ There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1939145
+ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=24787
+ https://github.com/AcademySoftwareFoundation/openexr/commit/eec0dba242bedd2778c973ae4af112107b33d9c9
CVE-2021-3476 created at 31 Mar 2021 07:26:43