AcademySoftwareFoundation.openexr is vulnerable to Information Disclosure
33
Low Risk
OpenEXRCore reconstructs pixel channels from an under-filled decode buffer for certain compressed EXR chunks, so uninitialized resource bytes can be copied into caller-visible output. A crafted EXR decoded through the normal library APIs can therefore disclose stale process memory via pixel data. The fix rejects undersized compressed or raw streams before reconstructing full channel rows.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted EXR files through OpenEXRCore.
AcademySoftwareFoundation.openexr is vulnerable to Information Disclosure in versions 3.1.0 - 3.4.13.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant