← Back to CVE List

CVE-2021-20296

Published: 2021-04-01T14:15Z
Last Modified: 2024-11-21T05:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt