An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Sep 23, 2020 | Jun 26, 2020 |
| Debian | — | Upgrade openexr | Jul 30, 2024 | Jun 26, 2020 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Jul 12, 2021 | Jun 26, 2020 |
| Suse | — | Upgrade libIlmImf-Imf_2_1-21-32bitUpgrade libIlmImf-Imf_2_1-21Upgrade openexrUpgrade OpenEXR-develUpgrade openexr-docUpgrade libilmimf-2_2-23-32bitUpgrade libIlmImf-2_2-23Upgrade libIlmImfUtil-2_2-23Upgrade libilmimfutil-2_2-23-32bit | Jul 17, 2020 | Jun 26, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub