6.8
CVSSv2

CVE-2017-9111

Published: 21/05/2017 Updated: 30/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that OpenEXR incorrectly handled certain malformed EXR image files. If a user were tricked into opening a crafted EXR image file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-12596)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openexr openexr 2.2.0

Vendor Advisories

Debian Bug report logs - #864078 openexr: CVE-2017-9110 CVE-2017-9112 CVE-2017-9116 Package: src:openexr; Maintainer for src:openexr is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 4 Jun 2017 06:48:02 UTC Severity: grave Tag ...
Debian Bug report logs - #873885 openexr: CVE-2017-9111 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 Package: src:openexr; Maintainer for src:openexr is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 4 Jun 2017 06:48:02 UTC Sever ...
Several security issues were fixed in OpenEXR ...
Several security issues were fixed in OpenEXR ...
Multiple security issues were found in the OpenEXR image library, which could result in denial of service and potentially the execution of arbitrary code when processing malformed EXR image files For the stable distribution (buster), these problems have been fixed in version 221-41+deb10u1 We recommend that you upgrade your openexr packages F ...
In OpenEXR 220, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReadingh could cause the application to crash or execute arbitrary code ...