Industrial Light & Magic · Openexr · CVE-2017-9114
**Name of the Vulnerable Software and Affected Versions**
OpenEXR version 2.2.0
**Description**
The issue is related to an invalid read operation in the `refill` function of the `ImfFastHuf.cpp` component, which could cause the application to crash. This is due to a buffer overflow in memory, allowing a remote attacker to cause a denial of service.
**Recommendations**
For OpenEXR version 2.2.0, consider applying a patch or fix to address the buffer overflow issue in the `refill` function of the `ImfFastHuf.cpp` component.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.