First published: Sun May 21 2017(Updated: )
In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openexr Openexr | =2.2.0 | |
debian/openexr | 2.5.4-2+deb11u1 3.1.5-5 3.1.5-5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9111 is a vulnerability in OpenEXR 2.2.0 that can cause a crash or allow arbitrary code execution.
CVE-2017-9111 has a severity rating of 8.8, which is considered high.
The affected software for CVE-2017-9111 includes OpenEXR 2.2.0 to 2.5.4-2, and 3.1.5-5 to 3.1.5-5.1.
To fix CVE-2017-9111, update OpenEXR to version 2.2.1-4.1+deb10u1, 2.2.1-4.1+deb10u2, 2.5.4-2+deb11u1, or 3.1.5-5.1.
You can find more information about CVE-2017-9111 at the following references: [Link 1](https://www.openwall.com/lists/oss-security/2017/05/12/5), [Link 2](https://github.com/openexr/openexr/issues/232), [Link 3](https://github.com/AcademySoftwareFoundation/openexr/pull/401#issuecomment-513721310).