9.1
CVSSv3

CVE-2023-5841

Published: 01/02/2024 Updated: 26/02/2024
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

Vulnerable Product Search on Vulmon Subscribe to Product

openexr openexr

Vendor Advisories

Debian Bug report logs - #1063414 openexr: CVE-2023-5841 Package: src:openexr; Maintainer for src:openexr is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 7 Feb 2024 21:21:02 UTC Severity: important Tags: security, upstr ...
Description<!---->This CVE is under investigation by Red Hat Product Security ...