An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openexr | Sep 23, 2020 | Jun 26, 2020 |
| Debian | — | Upgrade openexr | Aug 31, 2020 | Jun 26, 2020 |
| Gentoo Linux | — | Upgrade media-libs/openexr. | Jul 12, 2021 | Jun 26, 2020 |
| Huawei Euleros 2_0_sp8 | — | — | Oct 11, 2022 | Jun 26, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 26, 2020 |
| Suse | — | Upgrade libIlmImfUtil-2_2-23Upgrade libIlmImf-Imf_2_1-21-32bitUpgrade libilmimfutil-2_2-23-32bitUpgrade libIlmImf-2_2-23Upgrade openexr-docUpgrade libilmimf-2_2-23-32bitUpgrade libIlmImf-Imf_2_1-21Upgrade OpenEXR-develUpgrade openexr | Jul 17, 2020 | Jun 26, 2020 |
| Ubuntu | — | Upgrade libopenexr23Upgrade libopenexr24Upgrade libopenexr22Upgrade openexr | Aug 5, 2020 | Jun 26, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub