Vulnerability Information: - ID: Bug 1939149, CVE-2021-3479 - Description: OpenEXR: Out-of-memory caused by allocation of a very large buffer - Reported Date: March 15, 2021 - Status: Closed WONTFIX - Priority: Medium - Severity: Medium Affected Versions: - Fixed in versions: OpenEXR 3.0.0-beta, OpenEXR 2.4.3 - Also fixed in OpenEXR v2.5.4, v2.5.5, and v3.0.1 and beyond, and v2.4.3 Associated Links: - External Reference: Chromium OSS Fuzz Issue #25370 - Upstream Patch Commit: GitHub Commit - PR Explanation: GitHub Pull Request #830