OpenEXR is vulnerable to Out-of-bounds Read
55
Medium Risk
OpenEXR's HTJ2K decoder, embedded in the PyPI OpenEXR extension, parses a chunk header-length field (PLEN) and advances the compressed-buffer pointer without rejecting values larger than the available compressed data. A crafted HTJ2K EXR with an oversized PLEN causes an out-of-bounds read during decode through the Python bindings. The fix validates the HTJ2K chunk header length before decode.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted HTJ2K-compressed EXR files through the OpenEXR Python bindings.
OpenEXR is vulnerable to Out-of-bounds Read in versions 3.4.0 - 3.4.12.
Upgrade the OpenEXR library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant