First published: Sun May 21 2017(Updated: )
In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openexr Openexr | =2.2.0 | |
debian/openexr | 2.5.4-2+deb11u1 3.1.5-5 3.1.5-5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9110 is a vulnerability in OpenEXR 2.2.0 that can cause an application to crash due to an invalid read of size 2 in the hufDecode function in ImfHuf.cpp.
CVE-2017-9110 has a severity rating of medium with a score of 6.5.
CVE-2017-9110 can be exploited by causing the application to process a specially crafted image file that triggers the invalid read in the hufDecode function.
Yes, OpenEXR 2.2.0 is the only affected version of the software.
Yes, a fix for CVE-2017-9110 is available in the form of a patch that can be applied to OpenEXR 2.2.0.