Intel

AIKIDO-2024-10442

AcademySoftwareFoundation.openexr is vulnerable to NULL Pointer Dereference

NULL Pointer Dereference Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 13, 2024

21

Low Risk

This Affects:

c++AcademySoftwareFoundation.openexr
3.1.0 - 3.3.1
Fixed in 3.3.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a null-dereference WRITE in the Imf_3_4::ScanLineProcess::run_fill function. This flaw can lead to crashes, potentially causing a Denial of Service (DoS). Proper handling of null values is necessary to prevent such issues, as it could result in system instability or unresponsiveness when exploited.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

AcademySoftwareFoundation.openexr is vulnerable to NULL Pointer Dereference in versions 3.1.0 - 3.3.1.

How to fix this

Upgrade the AcademySoftwareFoundation.openexr library to the patch version.