In OpenEXR 2.2.0, an invalid write of size 1 in the bufferedReadPixels function in ImfInputFile.cpp could cause the application to crash or execute arbitrary code.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Aug 22, 2024 | May 21, 2017 |
| Debian | — | Upgrade openexr | Aug 31, 2020 | May 21, 2017 |
| Freebsd | — | Upgrade openexr | May 25, 2017 | May 25, 2017 |
| Huawei Euleros 2_0_sp2 | — | — | Feb 22, 2021 | May 21, 2017 |
| Huawei Euleros 2_0_sp3 | — | — | Dec 18, 2019 | May 21, 2017 |
| Huawei Euleros 2_0_sp5 | — | — | Feb 3, 2021 | May 21, 2017 |
| Huawei Euleros 2_0_sp8 | — | — | May 27, 2020 | May 21, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | May 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 12, 2017 |
| Suse | — | Upgrade libIlmImf-2_2-23Upgrade libilmimfutil-2_2-23-32bitUpgrade OpenEXR-develUpgrade openexrUpgrade libIlmImf-Imf_2_1-21Upgrade openexr-docUpgrade libIlmImfUtil-2_2-23Upgrade libilmimf-2_2-23-32bitUpgrade libIlmImf-Imf_2_1-21-32bit | May 20, 2018 | May 21, 2017 |
| Ubuntu | — | Upgrade libopenexr22Upgrade openexrUpgrade libopenexr24Upgrade libopenexr23 | Oct 8, 2019 | May 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub