PT-2026-81479 · Openexr · Openexr
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenEXR versions prior to 3.2.11
OpenEXR versions 3.3.0 through 3.3.12
OpenEXR versions 3.4.0 through 3.4.13
Description
OpenEXR, the reference implementation for the EXR image format, is subject to a crash when processing a specially crafted EXR file. The issue occurs when the function
Imf::GetChannelsInMultiPartFile() processes a file with an empty multiView header attribute, leading the function Imf::viewFromChannelName() to index an empty vector for a dotless channel name.Recommendations
Update to version 3.2.11.
Update to version 3.3.13.
Update to version 3.4.14.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openexr