OpenEXR is vulnerable to Information Disclosure
43
Medium Risk
OpenEXRCore's HTJ2K decoder, shipped in the PyPI OpenEXR extension, verifies that each channel-map index is in range but does not require the map to be a permutation. A malformed HTJ2K EXR can map several components onto one channel and leave others unwritten in an uninitialized scratch buffer that is then returned to the caller. The fix rejects any channel map that is not a strict permutation before decoded data is copied.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted EXR files that use HTJ2K compression through the OpenEXR Python bindings.
OpenEXR is vulnerable to Information Disclosure in versions 3.4.0 - 3.4.13.
Upgrade the OpenEXR library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant