Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputFile function in IlmImf/ImfCRgbaFile.cpp. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution existsUpgrade openexr | May 15, 2025 | May 15, 2025 |
| Huawei Euleros 2_0_sp3 | — | — | Apr 16, 2020 | Oct 3, 2017 |
| Huawei Euleros 2_0_sp8 | — | — | May 27, 2020 | Oct 3, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 27, 2017 |
| Suse | — | Upgrade libIlmImf-2_2-23Upgrade libilmimf-2_2-23-32bitUpgrade openexrUpgrade libIlmImf-Imf_2_1-21-32bitUpgrade libilmimfutil-2_2-23-32bitUpgrade libIlmImf-Imf_2_1-21Upgrade OpenEXR-develUpgrade openexr-docUpgrade libIlmImfUtil-2_2-23 | Jul 30, 2019 | Oct 2, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub