AcademySoftwareFoundation.openexr is vulnerable to Information Disclosure
33
Low Risk
OpenEXRCore's DWAA/DWAB decoder accepts a valid but too-short DWA RLE raw stream for an RLE-classified channel. The decoder expands only the attacker-declared RLE_RAW_SIZE and then reconstructs the full channel from the planar buffer, copying uninitialized tail bytes into caller-visible pixels. The fix rejects undersized compressed or raw streams before reconstructing full channel rows.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted DWAA/DWAB-compressed EXR files.
AcademySoftwareFoundation.openexr is vulnerable to Information Disclosure in versions 3.1.0 - 3.4.13.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant