An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Aug 22, 2024 | Apr 14, 2020 |
| Amazon Linux Ami 2 | — | Upgrade OpenEXR-debuginfoUpgrade OpenEXR-libsUpgrade OpenEXRUpgrade OpenEXR-devel | Oct 28, 2020 | Apr 14, 2020 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Sep 9, 2020 | Apr 14, 2020 |
| Apple Osx Imageio | — | Apply OS X security update 2020-004 High SierraApply OS X security update 2020-004 MojaveUpgrade macOS to the latest version | Sep 9, 2020 | Apr 14, 2020 |
| Centos_linux | — | Upgrade OpenEXR-develUpgrade OpenEXRUpgrade OpenEXR-debuginfoUpgrade OpenEXR-libs | Oct 1, 2020 | Apr 14, 2020 |
| Debian | — | Upgrade openexr | Aug 31, 2020 | Apr 14, 2020 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Jul 12, 2021 | Apr 14, 2020 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Apr 14, 2020 |
| Oracle_linux | — | Upgrade openexr-libsUpgrade openexr-develUpgrade openexr | Oct 7, 2020 | Feb 8, 2020 |
| Redhat_linux | — | Upgrade openexr-debuginfoUpgrade openexr-libsNo solution existsUpgrade openexr-develUpgrade openexr | Oct 1, 2020 | Apr 14, 2020 |
| Suse | — | Upgrade libilmimf-2_2-23Upgrade openexrUpgrade openexr-develUpgrade libilmimfutil-2_2-23-32bitUpgrade libilmimf-2_2-23-32bitUpgrade openexr-docUpgrade libilmimfutil-2_2-23 | May 23, 2020 | Apr 14, 2020 |
| Ubuntu | — | Upgrade libopenexr23Upgrade openexrUpgrade libopenexr22Upgrade libopenexr24 | Apr 28, 2020 | Apr 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub