AcademySoftwareFoundation.openexr is vulnerable to Out-of-bounds Write
70
High Risk
On ILP32 builds, TiledRgbaInputFile large-tile handling computes Array2D allocation sizes from attacker-controlled tile dimensions using 32-bit arithmetic. A crafted tiled EXR with oversized tiles can overflow the size computation, undersize the Array2D, and write heap data out of bounds while reading tiles. Typical 64-bit builds are not affected. The fix rejects oversized tile allocation requests before the Array2D is created.
You are affected if you are using a version that falls within the vulnerable range and you run a 32-bit (ILP32) build that reads untrusted tiled EXR files through TiledRgbaInputFile.
AcademySoftwareFoundation.openexr is vulnerable to Out-of-bounds Write in versions 3.3.0 - 3.3.12 and 3.4.0 - 3.4.13.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant