Back

HIGH

OpenEXR: Multiple integer overflows

Published Jul 31, 2009

Description

Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 31, 2009
Updated Aug 7, 2024
Reserved May 20, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 28, 2009