PT-2017-4138 · Industrial Light & Magic+2 · Openexr+2

Binarycrusader

·

Published

2017-05-21

·

Updated

2021-03-05

·

CVE-2017-9114

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR version 2.2.0
Description The issue is related to an invalid read operation in the refill function of the ImfFastHuf.cpp component, which could cause the application to crash. This is due to a buffer overflow in memory, allowing a remote attacker to cause a denial of service.
Recommendations For OpenEXR version 2.2.0, consider applying a patch or fix to address the buffer overflow issue in the refill function of the ImfFastHuf.cpp component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1211
ALT-PU-2019-2753
ALT-PU-2019-2754
ALT-PU-2019-2756
ALT-PU-2019-2757
BDU:2021-03496
CVE-2017-9114
DLA-1083-1
DLA-2358-1
DSA-4755-1
OESA-2021-1060
SUSE-SU-2018:0585-1
SUSE-SU-2018:0587-1

Affected Products

Alt Linux
Openexr
Suse