Описание
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.
A flaw was found in OpenEXR, an image storage format for the motion picture industry. A remote attacker or local user could exploit this vulnerability by providing a specially crafted B44 or B44A EXR file. This crafted file can cause an out-of-bounds write during file decoding, which may lead to memory corruption and potentially arbitrary code execution or, most likely, an application crash (Denial of Service).
Отчет
This Moderate impact flaw in OpenEXR affects Red Hat products that process EXR image files. A specially crafted B44 or B44A EXR file can trigger an out-of-bounds write during decoding, potentially leading to memory corruption and application crashes. Exploitation requires user interaction with a malicious file.
Меры по смягчению последствий
To mitigate this issue, avoid processing untrusted B44 or B44A EXR image files with applications linked against the OpenEXR library. Restricting the source of EXR files to trusted origins can reduce the risk of exploitation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | openexr | Affected | ||
| Red Hat Enterprise Linux 6 | OpenEXR | Out of support scope | ||
| Red Hat Enterprise Linux 7 | OpenEXR | Not affected | ||
| Red Hat Enterprise Linux 8 | OpenEXR | Not affected | ||
| Red Hat Enterprise Linux 9 | openexr | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.6 Medium
CVSS3
Связанные уязвимости
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.
OpenEXR provides the specification and reference implementation of the ...
OpenEXR: integer overflow to OOB write in uncompress_b44_impl()
EPSS
6.6 Medium
CVSS3