AcademySoftwareFoundation.openexr is vulnerable to Out-of-bounds Write
61
Medium Risk
OpenEXRUtil's FlatImageChannel row addressing assumed a data window originating at (0, 0). Crafted EXR files with a nonzero data-window origin (or related subsampled layouts) make row-address computations land outside the allocated channel buffer, producing a heap out-of-bounds write while reading the image through OpenEXRUtil. The fix computes row pointers from the actual data-window origin.
You are affected if you are using a version that falls within the vulnerable range and you use OpenEXRUtil FlatImageChannel APIs to read untrusted EXR files whose data window does not start at the origin.
AcademySoftwareFoundation.openexr is vulnerable to Out-of-bounds Write in versions 3.3.0 - 3.3.12 and 3.4.0 - 3.4.13.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant