CVE-2021-20300 PUBLISHED

A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.

EPSS 0.39% · 60.1th percentile

Risk Scores

EPSS Score
0.39%
60.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSopenexr2.2.1-4.1ubuntu1, 0, 2.3.0-6ubuntu0.1
Ubuntu:18.04:LTSopenexr2.2.0-11.1ubuntu1.4, 2.2.0-11.1ubuntu1.1, 2.2.0-11ubuntu1
Ubuntu:Pro:16.04:LTSopenexr2.2.0-10ubuntu2.1, 2.2.0-10ubuntu2, 2.2.0-9ubuntu1

Timeline

References

Open in Interactive Console →