AcademySoftwareFoundation.openexr is vulnerable to Information Disclosure
43
Medium Risk
OpenEXRCore decodes HTJ2K-compressed images using a channel map that assigns codestream components to file channels. The decoder verifies that each mapped index is in range but does not require the map to be a permutation, so a malformed file can point several components at one channel and leave other channels unwritten in an uninitialized scratch buffer. Those unwritten channels are then copied to the caller, disclosing stale heap contents. The fix rejects any channel map that is not a strict permutation before decoded data is copied.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted EXR files that use HTJ2K compression.
AcademySoftwareFoundation.openexr is vulnerable to Information Disclosure in versions 3.4.0 - 3.4.13.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant