CVE-2017-12596: High severity OpenEXR OpenEXR vulnerability
Published Aug 7, 2017
·Updated
In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.
Affected Software
2 affected componentsFixes available
OpenEXR OpenEXR=2.2.0
debian/openexr
2.5.4-2+deb11u13.1.5-53.1.13-23.4.6+ds-4
Remediation
Event History
Aug 7, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:27 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:34 PM
RemedyDescriptionSeverityAffected Software
Mar 19, 2026
Data Sourced
via Debian·08:56 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2017-12596?
CVE-2017-12596 is a vulnerability in OpenEXR 2.2.0 that allows a crafted image to cause a heap-based buffer over-read in the hufDecode function.
2
What is the impact of CVE-2017-12596?
The vulnerability may result in denial of service or possibly other unspecified impacts.
3
How can I fix CVE-2017-12596 in OpenEXR?
To fix CVE-2017-12596, update OpenEXR to version 2.3.0 or apply the appropriate remedies provided by the vendor.
4
Where can I find more information about CVE-2017-12596?
You can find more information about CVE-2017-12596 on the OpenEXR GitHub page and the provided references.
5
What is the severity of CVE-2017-12596?
CVE-2017-12596 has a severity rating of 7.8 (high).