AcademySoftwareFoundation.openexr is vulnerable to Out-of-bounds Read
55
Medium Risk
OpenEXRUtil's SampleCountChannel row addressing assumed a data window originating at (0, 0). Crafted EXR files with a nonzero data-window origin (or related subsampled layouts) make row-address computations land outside the allocated channel buffer, producing a heap out-of-bounds read while reading the image through OpenEXRUtil. The fix computes row pointers from the actual data-window origin.
You are affected if you are using a version that falls within the vulnerable range and you use OpenEXRUtil SampleCountChannel APIs to read untrusted EXR files whose data window does not start at the origin.
AcademySoftwareFoundation.openexr is vulnerable to Out-of-bounds Read in versions 3.3.0 - 3.3.12 and 3.4.0 - 3.4.13.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant