First published: Sun May 21 2017(Updated: )
In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip.cpp could cause the application to crash.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openexr Openexr | =2.2.0 | |
debian/openexr | 2.5.4-2+deb11u1 3.1.5-5 3.1.5-5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9116 is a vulnerability in OpenEXR 2.2.0 that could cause the application to crash.
The severity of CVE-2017-9116 is medium with a CVSS score of 6.5.
To fix this vulnerability, you should update OpenEXR to a version that is not affected, if available.
You can find more information about CVE-2017-9116 at the following references: [Link 1](http://www.openwall.com/lists/oss-security/2017/05/12/5), [Link 2](https://github.com/openexr/openexr/issues/232), [Link 3](https://github.com/openexr/openexr/pull/233)