Back to bug 1970991

Who When What Removed Added
Pedro Sampaio 2021-06-11 15:43:20 UTC Depends On 1970994, 1970993
Pedro Sampaio 2021-06-11 15:43:57 UTC Blocks 1970995
Shawn Jamison 2021-06-14 15:23:07 UTC Priority medium low
Severity medium low
Shawn Jamison 2021-06-14 15:32:28 UTC Doc Text There's a flaw in OpenEXR's rleUncompress functionality. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
Guilherme de Almeida Suckevicz 2021-06-15 17:48:01 UTC Summary OpenEXR: Heap buffer overflow in the rleUncompress function CVE-2021-3605 OpenEXR: Heap buffer overflow in the rleUncompress function
Alias CVE-2021-3605
Guilherme de Almeida Suckevicz 2021-06-15 17:48:32 UTC Blocks 1972358
Shawn Jamison 2021-06-17 20:04:24 UTC Depends On 1973435, 1973434
Salvatore Bonaccorso 2021-06-27 12:22:12 UTC CC carnil
Flags needinfo?(psampaio)
Pedro Sampaio 2021-06-28 15:13:57 UTC CC sjamison
Flags needinfo?(psampaio) needinfo?(sjamison)
Shawn Jamison 2021-06-28 15:58:33 UTC Status NEW CLOSED
Resolution --- DUPLICATE
Last Closed 2021-06-28 15:58:33 UTC
Shawn Jamison 2021-06-28 15:59:59 UTC Flags needinfo?(sjamison)
Shawn Jamison 2021-06-28 16:15:50 UTC Depends On 1834513
Shawn Jamison 2021-06-28 18:13:01 UTC Depends On 1834514
Salvatore Bonaccorso 2021-07-06 12:51:34 UTC Flags needinfo?(psampaio)
Pedro Sampaio 2021-07-07 20:12:57 UTC Flags needinfo?(psampaio) needinfo?(sjamison)
Shawn Jamison 2021-07-19 21:49:36 UTC Status CLOSED NEW
Resolution DUPLICATE ---
Keywords Reopened
Shawn Jamison 2021-07-19 21:49:50 UTC Flags needinfo?(sjamison)
Shawn Jamison 2021-07-19 21:54:06 UTC Flags needinfo?(psampaio)
Guilherme de Almeida Suckevicz 2021-07-22 13:41:34 UTC Flags needinfo?(psampaio)
Shawn Jamison 2021-08-06 18:29:10 UTC Fixed In Version OpenEXR 3.0.5
Shawn Jamison 2021-08-06 18:31:04 UTC Depends On 1990996
Todd Cullum 2021-08-06 18:55:32 UTC Depends On 1834514
Nicolas Chauvet (kwizart) 2021-12-21 08:11:28 UTC CC kwizart
Red Hat Bugzilla 2023-07-07 08:35:28 UTC Assignee security-response-team nobody

Back to bug 1970991