CVE-2009-1721: Medium severity OpenEXR OpenEXR vulnerability
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1721?
CVE-2009-1721 is classified as a high severity vulnerability that can lead to denial of service or potentially allow arbitrary code execution.
How do I fix CVE-2009-1721?
To fix CVE-2009-1721, it is recommended to update OpenEXR to a patched version that addresses this vulnerability.
Which versions of OpenEXR are affected by CVE-2009-1721?
CVE-2009-1721 affects OpenEXR versions 1.2.2 and 1.6.1.
What type of attack does CVE-2009-1721 facilitate?
CVE-2009-1721 facilitates denial of service attacks and may allow attackers to execute arbitrary code.
Is CVE-2009-1721 present in any Linux distributions?
Yes, CVE-2009-1721 is present in various Linux distributions, including specific versions of Debian, Ubuntu, and openSUSE.