Vulnerability Details CVE-2021-3933
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.4%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
Products affected by CVE-2021-3933
-
cpe:2.3:a:openexr:openexr:-
-
cpe:2.3:a:openexr:openexr:1.0
-
cpe:2.3:a:openexr:openexr:1.0.1
-
cpe:2.3:a:openexr:openexr:1.0.2
-
cpe:2.3:a:openexr:openexr:1.0.3
-
cpe:2.3:a:openexr:openexr:1.0.4
-
cpe:2.3:a:openexr:openexr:1.0.5
-
cpe:2.3:a:openexr:openexr:1.0.6
-
cpe:2.3:a:openexr:openexr:1.0.7
-
cpe:2.3:a:openexr:openexr:1.1.0
-
cpe:2.3:a:openexr:openexr:1.1.1
-
cpe:2.3:a:openexr:openexr:1.2.1
-
cpe:2.3:a:openexr:openexr:1.2.2
-
cpe:2.3:a:openexr:openexr:1.3.0
-
cpe:2.3:a:openexr:openexr:1.3.1
-
cpe:2.3:a:openexr:openexr:1.3.2
-
cpe:2.3:a:openexr:openexr:1.4.0
-
cpe:2.3:a:openexr:openexr:1.5.0
-
cpe:2.3:a:openexr:openexr:1.6.0
-
cpe:2.3:a:openexr:openexr:1.6.1
-
cpe:2.3:a:openexr:openexr:1.7.0
-
cpe:2.3:a:openexr:openexr:1.7.1
-
cpe:2.3:a:openexr:openexr:2.0.0
-
cpe:2.3:a:openexr:openexr:2.0.1
-
cpe:2.3:a:openexr:openexr:2.1.0
-
cpe:2.3:a:openexr:openexr:2.2.0
-
cpe:2.3:a:openexr:openexr:2.2.1
-
cpe:2.3:a:openexr:openexr:2.2.2
-
cpe:2.3:a:openexr:openexr:2.3.0
-
cpe:2.3:a:openexr:openexr:2.4.0
-
cpe:2.3:a:openexr:openexr:2.4.1
-
cpe:2.3:a:openexr:openexr:2.4.2
-
cpe:2.3:a:openexr:openexr:2.4.3
-
cpe:2.3:a:openexr:openexr:2.5.0
-
cpe:2.3:a:openexr:openexr:2.5.1
-
cpe:2.3:a:openexr:openexr:2.5.10
-
cpe:2.3:a:openexr:openexr:2.5.2
-
cpe:2.3:a:openexr:openexr:2.5.3
-
cpe:2.3:a:openexr:openexr:2.5.4
-
cpe:2.3:a:openexr:openexr:2.5.5
-
cpe:2.3:a:openexr:openexr:2.5.6
-
cpe:2.3:a:openexr:openexr:2.5.7
-
cpe:2.3:a:openexr:openexr:2.5.8
-
cpe:2.3:a:openexr:openexr:2.5.9
-
cpe:2.3:a:openexr:openexr:3.0.0
-
cpe:2.3:a:openexr:openexr:3.0.1
-
cpe:2.3:a:openexr:openexr:3.0.2
-
cpe:2.3:a:openexr:openexr:3.0.3
-
cpe:2.3:a:openexr:openexr:3.0.4
-
cpe:2.3:a:openexr:openexr:3.0.5
-
cpe:2.3:a:openexr:openexr:3.1.0
-
cpe:2.3:a:openexr:openexr:3.1.1
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:11.0
-
cpe:2.3:o:fedoraproject:fedora:36