Ilmbase · Openexr · CVE-2020-15305
**Name of the Vulnerable Software and Affected Versions**
OpenEXR versions prior to 2.5.2
**Description**
An issue in OpenEXR is related to the use of memory after it has been freed, specifically in the `DeepScanLineInputFile::DeepScanLineInputFile()` function. This can be caused by invalid input and may lead to a denial of service. The estimated number of potentially affected devices and details about real-world incidents are not provided.
**Recommendations**
For versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `DeepScanLineInputFile::DeepScanLineInputFile()` function until a patch is available.