AcademySoftwareFoundation.openexr is vulnerable to Integer Overflow
82
High Risk
Affected versions of this package are vulnerable to memory corruption when decoding DWA-compressed EXR files. A signed 32-bit multiplication of channel width and bytes-per-element can overflow for crafted dimensions, shifting the end-of-buffer guard and letting the decoder write past the buffer end.
You are affected if you are using a version that falls within the vulnerable range.
AcademySoftwareFoundation.openexr is vulnerable to Integer Overflow in versions 3.4.0 - 3.4.9, 3.3.0 - 3.3.9 and 3.2.0 - 3.2.7.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant