Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Binarycrusader

#40789of 53,624
6.5Total CVSS
Vulnerabilities · 1
PT-2017-4138
6.5
2017-05-21
Industrial Light & Magic · Openexr · CVE-2017-9114
**Name of the Vulnerable Software and Affected Versions** OpenEXR version 2.2.0 **Description** The issue is related to an invalid read operation in the `refill` function of the `ImfFastHuf.cpp` component, which could cause the application to crash. This is due to a buffer overflow in memory, allowing a remote attacker to cause a denial of service. **Recommendations** For OpenEXR version 2.2.0, consider applying a patch or fix to address the buffer overflow issue in the `refill` function of the `ImfFastHuf.cpp` component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.