OESA-2024-1217
Dashboard / Vulnerabilities / OESA-2024-1217
Summary: OpenEXR security update
Details: OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light & Magic for use in computer imaging applications. Security Fix(es): Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library. (CVE-2023-5841)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1217, https://nvd.nist.gov/vuln/detail/CVE-2023-5841
Affected packages
Package
Name: OpenEXR
Purl: pkg:rpm/openEuler/OpenEXR&distro=openEuler-22.03-LTS-SP2
Affected ranges
Type: ECOSYSTEM
Events:
