PT-2025-40879 · Openexr+4 · Openexr+4
CVE-2025-59733
·
Publicado
2025-08-25
·
Atualizado
2026-08-07
CVSS v4.0
8.7
Alta
| Vetor | AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenEXR versions prior to 8.0
Description
An issue exists in decoding OpenEXR files that use DWAA or DWAB compression. The software makes an assumption that all image channels have the same pixel type and size, specifically expecting "B", "G", "R", and "A" channels when four channels are present. The
dwa uncompress function calculates buffer sizes based on this assumption. If main color channels are set to a 4-byte type and additional channels of a 2-byte type are added, the calculation can result in exceeding the allocated buffer, potentially leading to issues. The vulnerable code is located in the decode header and dwa uncompress functions, and involves the td->uncompressed data buffer.Recommendations
Upgrade to version 8.0 or beyond.
Exploit
Correção
DoS
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Linuxmint
Openexr
Red Os
Ubuntu