In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-openexr | Aug 22, 2024 | May 21, 2017 | |
| Debian | debian-upgrade-openexr | Feb 25, 2019 | May 21, 2017 | |
| Freebsd | freebsd-upgrade-package-openexr | May 25, 2017 | May 25, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-openexr-libs | Dec 4, 2019 | May 21, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-openexr-libs | Dec 18, 2019 | May 21, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-openexr-libs | Feb 3, 2021 | May 21, 2017 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-openexr-libs | May 27, 2020 | May 21, 2017 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-entire-11-4-11-4-0-0-1-15-0 | Oct 19, 2018 | May 21, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | May 12, 2017 | |
| Suse | — | suse-upgrade-libilmimf-2_2-23suse-upgrade-libilmimf-imf_2_1-21suse-upgrade-libilmimf-imf_2_1-21-32bitsuse-upgrade-libilmimfutil-2_2-23suse-upgrade-openexrsuse-upgrade-openexr-32bitsuse-upgrade-openexr-develsuse-upgrade-openexr-x86 | Mar 10, 2018 | May 21, 2017 |
| Ubuntu | ubuntu-upgrade-libopenexr22ubuntu-upgrade-libopenexr23ubuntu-upgrade-openexr | Oct 8, 2019 | May 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub