Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-48073

Опубликовано: 31 июл. 2025
Источник: debian
EPSS Низкий

Описание

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openexrnot-affectedpackage

Примечания

  • Introduced with: https://github.com/AcademySoftwareFoundation/openexr/commit/2cbed131364fb8b1bc356940a5a4294f01f02a17 (v3.3.0-rc0)

  • https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-qhpm-86v7-phmm

EPSS

Процентиль: 3%
0.00019
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
17 дней назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.

CVSS3: 3.3
redhat
17 дней назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.

CVSS3: 6.2
nvd
17 дней назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.

github
17 дней назад

OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode

EPSS

Процентиль: 3%
0.00019
Низкий