PT-2009-6685 · Openexr · Libopenexr-Dev+3
Chris Ries
+1
·
Published
1970-01-01
·
Updated
2012-10-23
·
CVE-2009-1722
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libopenexr6 versions (affected versions not specified)
libopenexr2c2a versions (affected versions not specified)
libopenexr-dev versions (affected versions not specified)
OpenEXR version 1.2.2
Description
The issue affects the compression implementation in OpenEXR, allowing context-dependent attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely.
Recommendations
For libopenexr6, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For libopenexr2c2a, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For libopenexr-dev, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For OpenEXR version 1.2.2, consider updating to a version that fixes the heap-based buffer overflow in the compression implementation to prevent potential denial of service or arbitrary code execution.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openexr
Libopenexr-Dev
Libopenexr2C2A
Libopenexr6