OpenEXR is vulnerable to Information Disclosure
43
Medium Risk
OpenEXRCore's deep-scanline reader, embedded in the PyPI OpenEXR module, lacks the packed-size-equals-unpacked-size guard that the tiled deep path already applies for uncompressed chunks. A crafted uncompressed deep-scanline EXR with mismatched sizes leaves an unpacked buffer uninitialized and copies those bytes into the caller's pixel buffer. The fix adds the same size-equality guard to the scanline chunk reader.
You are affected if you are using a version that falls within the vulnerable range and you decode untrusted uncompressed deep-scanline EXR files through the OpenEXR Python bindings.
OpenEXR is vulnerable to Information Disclosure in versions 3.2.3 - 3.4.13.
Upgrade the OpenEXR library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant