CVE-2009-1720: Buffer Overflow
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1720?
CVE-2009-1720 is classified as having moderate severity due to its potential to cause denial of service and execute arbitrary code.
How do I fix CVE-2009-1720?
To fix CVE-2009-1720, users should upgrade to a patched version of OpenEXR, specifically versions later than 1.6.1.
What are the affected versions in CVE-2009-1720?
CVE-2009-1720 affects OpenEXR versions 1.2.2 and 1.6.1.
What type of vulnerabilities are associated with CVE-2009-1720?
CVE-2009-1720 is associated with multiple integer overflows that can lead to heap-based buffer overflows.
Can CVE-2009-1720 be exploited remotely?
Yes, CVE-2009-1720 can be potentially exploited by context-dependent attackers, making it a concern for security.