OpenEXR is vulnerable to Out-of-bounds Read
75
High Risk
Affected versions of openexr contain an out-of-bounds read vulnerability in IDManifest::init() when processing prefix-compressed strings. A specially crafted .exr file can trigger reads beyond the bounds of a heap-allocated string buffer, potentially leading to information disclosure or denial of service through application crashes.
You are affected if you are using a version that falls within the vulnerable range.
OpenEXR is vulnerable to Out-of-bounds Read in versions 3.0.0 - 3.2.8, 3.3.0 - 3.3.10 and 3.4.0 - 3.4.10.
Upgrade the OpenEXR library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant