OpenEXR is vulnerable to Integer Overflow
75
High Risk
Affected versions of openexr contain an integer overflow vulnerability in readVariableLengthInteger() when parsing variable-length integers from untrusted EXR files. A specially crafted file can trigger undefined behavior through an oversized bit shift, potentially leading to out-of-bounds reads, memory corruption, or denial of service during file parsing.
You are affected if you are using a version that falls within the vulnerable range.
OpenEXR is vulnerable to Integer Overflow in versions 3.0.0 - 3.2.8, 3.3.0 - 3.3.10 and 3.4.0 - 3.4.10.
Upgrade the OpenEXR library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant