CVE-2017-9112: Medium severity OpenEXR OpenEXR vulnerability
Published May 21, 2017
·Updated
In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cpp could cause the application to crash.
Affected Software
3 affected componentsFixes available
OpenEXR OpenEXR=2.2.0
pip/OpenEXR<2.2.1
2.2.1
debian/openexr
2.5.4-2+deb11u13.1.5-53.1.13-23.4.6+ds-4
Remediation
Event History
May 21, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:17 AM
Jan 11, 2024
Data Sourced
via Launchpad·10:41 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:34 PM
RemedyDescriptionSeverityAffected Software
Mar 19, 2026
Data Sourced
via Debian·08:56 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-9112.
2
What is the severity of CVE-2017-9112?
The severity of CVE-2017-9112 is medium with a severity value of 6.5.
3
What is the affected software?
The affected software is OpenEXR version 2.2.0.
4
How can I fix CVE-2017-9112 in OpenEXR?
To fix CVE-2017-9112 in OpenEXR, update to version 2.2.1-4.1+deb10u1 or higher.
5
Where can I find more information about CVE-2017-9112?
You can find more information about CVE-2017-9112 at the following references: [1](http://www.openwall.com/lists/oss-security/2017/05/12/5), [2](https://github.com/openexr/openexr/issues/232), [3](https://github.com/openexr/openexr/pull/233).