PT-2026-81487 · Openexr · Openexr
CVSS v4.0
6.7
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenEXR versions 3.4.0 through 3.4.12
Description
The HTJ2K decoder fails to verify if the header-length field
PLEN parsed from a chunk's compressed data fits within the available buffer. During decoding, the codestream pointer is advanced by the size specified in PLEN and passed to the OpenJPH memory-input path. A crafted value in this field can push the pointer beyond the buffer boundary, resulting in an out-of-bounds read when processing untrusted files.Recommendations
Update to version 3.4.13.
Exploit
Fix
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openexr