AcademySoftwareFoundation.openexr is vulnerable to Stack-based Buffer Overflow
55
Medium Risk
OpenEXR's HTJ2K path accepts JPEG 2000 SIZ image-offset and tile-grid fields where the first tile does not intersect the declared image. A crafted HTJ2K EXR can therefore drive the vendored OpenJPH decoder into invalid tile geometry and a stack buffer overflow during decode. The fix rejects SIZ geometries whose first tile does not intersect the image before decode proceeds.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted HTJ2K-compressed EXR files.
AcademySoftwareFoundation.openexr is vulnerable to Stack-based Buffer Overflow in versions 3.4.0 - 3.4.13.
Upgrade the AcademySoftwareFoundation.openexr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant