First published: Sun May 21 2017(Updated: )
In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf.cpp could cause the application to crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openexr | 2.2.1-4.1+deb10u1 2.2.1-4.1+deb10u2 2.5.4-2+deb11u1 3.1.5-5 3.1.5-5.1 | |
OpenEXR | =2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9114 has a high severity due to the potential application crash caused by an invalid memory read.
To fix CVE-2017-9114, update OpenEXR to any of the following versions: 2.2.1-4.1+deb10u1, 2.2.1-4.1+deb10u2, 2.5.4-2+deb11u1, 3.1.5-5, or 3.1.5-5.1.
OpenEXR version 2.2.0 is affected by CVE-2017-9114.
Exploitation of CVE-2017-9114 may lead to application crashes resulting from invalid memory access.
Yes, CVE-2017-9114 has been publicly disclosed and is documented in security advisories.