CVE-2024-31047: Integer Overflow
Published Apr 8, 2024
·Updated
An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.
Affected Software
2 affected components
Academy Software Foundation OpenEXR<3.2.3
OpenEXR OpenEXR<3.2.4
Event History
Apr 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31047?
CVE-2024-31047 is considered a denial of service (DoS) vulnerability that can impact system availability.
2
How do I fix CVE-2024-31047?
To mitigate CVE-2024-31047, upgrade to a version of Academy Software Foundation OpenEXR later than 3.2.3.
3
Who is affected by CVE-2024-31047?
Users of Academy Software Foundation OpenEXR version 3.2.3 and earlier are vulnerable to CVE-2024-31047.
4
What type of attack is possible with CVE-2024-31047?
CVE-2024-31047 allows a local attacker to execute a denial of service attack via the convert function.
5
When was CVE-2024-31047 reported?
CVE-2024-31047 was reported in 2024, and details about its impact are documented in the vulnerability description.