CVE-2017-9111: High severity OpenEXR OpenEXR vulnerability
In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-9111?
CVE-2017-9111 is a vulnerability in OpenEXR 2.2.0 that can cause a crash or allow arbitrary code execution.
How severe is CVE-2017-9111?
CVE-2017-9111 has a severity rating of 8.8, which is considered high.
What is the affected software for CVE-2017-9111?
The affected software for CVE-2017-9111 includes OpenEXR 2.2.0 to 2.5.4-2, and 3.1.5-5 to 3.1.5-5.1.
How can CVE-2017-9111 be fixed?
To fix CVE-2017-9111, update OpenEXR to version 2.2.1-4.1+deb10u1, 2.2.1-4.1+deb10u2, 2.5.4-2+deb11u1, or 3.1.5-5.1.
Where can I find more information about CVE-2017-9111?
You can find more information about CVE-2017-9111 at the following references: [Link 1](https://www.openwall.com/lists/oss-security/2017/05/12/5), [Link 2](https://github.com/openexr/openexr/issues/232), [Link 3](https://github.com/AcademySoftwareFoundation/openexr/pull/401#issuecomment-513721310).