VYPR
Medium severity5.5NVD Advisory· Published Mar 31, 2021· Updated Jun 17, 2026

CVE-2021-3478

CVE-2021-3478

Description

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Openexr/Openexrv53 versions
    OpenEXR 3.0.0-beta+ 2 more
    • (no CPE)range: OpenEXR 3.0.0-beta
    • (no CPE)range: <3.0.0-beta
    • cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*range: <2.4.3
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.