An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Aug 22, 2024 | Apr 14, 2020 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Sep 9, 2020 | Sep 8, 2020 |
| Apple Osx Imageio | — | Apply Apple macOS Security Update 2020-004 MojaveApply Apple macOS Security Update 2020-004 High Sierra | Sep 9, 2020 | Sep 8, 2020 |
| Debian | — | Upgrade openexr | Aug 31, 2020 | Apr 14, 2020 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Jul 12, 2021 | Apr 14, 2020 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Apr 14, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 14, 2020 |
| Suse | — | Upgrade libilmimf-2_2-23-32bitUpgrade openexr-docUpgrade libIlmImfUtil-2_2-23Upgrade openexrUpgrade libilmimfutil-2_2-23-32bitUpgrade OpenEXR-develUpgrade libIlmImf-2_2-23 | May 23, 2020 | Apr 14, 2020 |
| Ubuntu | — | Upgrade libopenexr22Upgrade openexrUpgrade libopenexr24Upgrade libopenexr23 | Apr 28, 2020 | Apr 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub