VDB

DEBIAN-CVE-2021-23215

DEBIAN-CVE-2021-23215 PUBLISHED CVSS 5.5 MEDIUM

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:11openexr2.5.4-2, 0, 2.5.4-2
Debian:12openexr0, 0, 0
Debian:13openexr0, 0, 0
Debian:14openexr0, 0, 0

Timeline

  • Jun 8, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›