PT-2023-31504 · Unknown · Openexr-Viewer

Gap-Dev

·

Published

2023-12-11

·

Updated

2023-12-14

·

CVE-2023-50245

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR-viewer versions prior to 0.6.1
Description The issue is a memory overflow vulnerability in OpenEXR-viewer, a viewer for OpenEXR files with detailed metadata probing. This vulnerability is fixed in version 0.6.1.
Recommendations For versions prior to 0.6.1, update to version 0.6.1 to resolve the issue. At the moment, there is no other information about additional mitigation measures.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-50245
GHSA-99JG-R3F4-RPXJ

Affected Products

Openexr-Viewer