VDB
DEBIAN-CVE-2021-23215
DEBIAN-CVE-2021-23215
PUBLISHED
CVSS 5.5 MEDIUM
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | openexr | 2.5.4-2, 0, 2.5.4-2 |
| Debian:12 | openexr | 0, 0, 0 |
| Debian:13 | openexr | 0, 0, 0 |
| Debian:14 | openexr | 0, 0, 0 |
Timeline
- Jun 8, 2021 CVE Published
- Apr 28, 2026 CVE Updated