CVE-2017-9116: Medium severity OpenEXR OpenEXR vulnerability
Published May 21, 2017
·Updated
In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip.cpp could cause the application to crash.
Affected Software
2 affected componentsFixes available
OpenEXR OpenEXR=2.2.0
debian/openexr
2.5.4-2+deb11u13.1.5-53.1.13-23.4.6+ds-4
Remediation
Event History
May 21, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:42 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:34 PM
RemedyDescriptionSeverityAffected Software
Mar 22, 2026
Data Sourced
via Debian·09:01 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2017-9116?
CVE-2017-9116 is a vulnerability in OpenEXR 2.2.0 that could cause the application to crash.
2
How severe is the vulnerability CVE-2017-9116?
The severity of CVE-2017-9116 is medium with a CVSS score of 6.5.
3
How can I fix the vulnerability in OpenEXR 2.2.0 (CVE-2017-9116)?
To fix this vulnerability, you should update OpenEXR to a version that is not affected, if available.
4
Where can I find more information about CVE-2017-9116?
You can find more information about CVE-2017-9116 at the following references: [Link 1](http://www.openwall.com/lists/oss-security/2017/05/12/5), [Link 2](https://github.com/openexr/openexr/issues/232), [Link 3](https://github.com/openexr/openexr/pull/233)