CVE-2021-20299 PUBLISHED

A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

EPSS 1.03% · 77.2th percentile

Risk Scores

EPSS Score
1.03%
77.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSopenexr0, 2.2.0-7ubuntu1, 2.2.0-10ubuntu2
Ubuntu:Pro:20.04:LTSopenexr2.3.0-6ubuntu0.2, 0, 2.2.1-4.1ubuntu1
Ubuntu:18.04:LTSopenexr2.2.0-11.1ubuntu1.9, 2.2.0-11.1ubuntu1.2, 0

Timeline

References

Open in Interactive Console →