CVE-2009-1720
published 2009-07-31CVE-2009-1720: Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.44%
92.9th percentile
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openexr | < openexr 1.6.1-4.1 (bookworm) | openexr 1.6.1-4.1 (bookworm) |
| openexr | openexr | — | — |
| openexr | openexr | — | — |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qfx-pcxp-2cw7: Multiple integer overflows in OpenEXR 1
ghsa_unreviewed·2022-05-02
CVE-2009-1720 [HIGH] GHSA-9qfx-pcxp-2cw7: Multiple integer overflows in OpenEXR 1
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.
OSV
CVE-2009-1720: Multiple integer overflows in OpenEXR 1
osv·2009-07-31·CVSS 7.5
CVE-2009-1720 [HIGH] CVE-2009-1720: Multiple integer overflows in OpenEXR 1
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.
Ubuntu
OpenEXR vulnerabilities
vendor_ubuntu·2009-09-14·CVSS 7.5
CVE-2009-1720 [HIGH] OpenEXR vulnerabilities
Title: OpenEXR vulnerabilities
Summary: OpenEXR vulnerabilities
Drew Yao discovered several flaws in the way OpenEXR handled certain
malformed EXR image files. If a user were tricked into opening a crafted
EXR image file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1720, CVE-2009-1721)
It was discovered that OpenEXR did not properly handle certain malformed
EXR image files. If a user were tricked into opening a crafted EXR image
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-1722)
Instructions: In gene
Red Hat
OpenEXR: Multiple integer overflows
vendor_redhat·2009-07-28·CVSS 7.5
CVE-2009-1720 [HIGH] CWE-190 OpenEXR: Multiple integer overflows
OpenEXR: Multiple integer overflows
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.
Debian
CVE-2009-1720: openexr - Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent at...
vendor_debian·2009·CVSS 7.5
CVE-2009-1720 [HIGH] CVE-2009-1720: openexr - Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent at...
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1.6.1-4.1)
bullseye: resolved (fixed in 1.6.1-4.1)
forky: resolved (fixed in 1.6.1-4.1)
sid: resolved (fixed in 1.6.1-4.1)
trixie: resolved (fixed in 1.6.1-4.1)
No detection rules found.
Bugzilla
CVE-2009-1720 OpenEXR: Multiple integer overflows
bugzilla·2009-07-27·CVSS 7.5
CVE-2009-1720 [HIGH] CVE-2009-1720 OpenEXR: Multiple integer overflows
CVE-2009-1720 OpenEXR: Multiple integer overflows
Multiple integer overflow flaws, leading to heap-based buffer overflows
were found in OpenEXR. A remote attacker could provide a specially-crafted
image file, which once opened by a local, unsuspecting user, would lead
to denial of service ("exrmakepreview" crash), or potentially, arbitrary
code execution with the privileges of the user opening the image.
Credit: Drew Yao of Apple Product Security
Discussion:
Public now via:
http://seclists.org/fulldisclosure/2009/Jul/0444.html
---
This issue affects the versions of the OpenEXR package, as shipped
with Fedora releases of 10 and 11.
This issue affects the versions of the OpenEXR package, as shipped
with Extra Packages for Enterprise Linux 4 (EPEL4) and Extra
Packages for Enterprise L
Bugzilla
CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression
bugzilla·2009-07-27·CVSS 7.5
CVE-2009-1721 [HIGH] CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression
CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression
An invalid pointer free flaw was found in OpenEXR by Huffman decoding.
A remote attacker could provide a specially-crafted image file, which
once opened to a local, unsuspecting user would lead to denial of
service ("exrmakepreview" crash).
Credit: Drew Yao of Apple Product Security
Discussion:
Public now via:
http://seclists.org/fulldisclosure/2009/Jul/0444.html
---
This issue affects the versions of the OpenEXR package, as shipped
with Fedora releases of 10 and 11.
This issue affects the versions of the OpenEXR package, as shipped
with Extra Packages for Enterprise Linux 4 (EPEL4) and Extra
Packages for Enterprise Linux 5 (EPEL5) projects.
---
Created attachment 355419
Freeing unitialised pointers (CVE-2009-1721
http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-09/msg00000.htmlhttp://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiffhttp://secunia.com/advisories/36030http://secunia.com/advisories/36032http://secunia.com/advisories/36096http://secunia.com/advisories/36123http://secunia.com/advisories/36753http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gzhttp://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gzhttp://support.apple.com/kb/HT3757http://www.debian.org/security/2009/dsa-1842http://www.mandriva.com/security/advisories?name=MDVSA-2009:190http://www.mandriva.com/security/advisories?name=MDVSA-2009:191http://www.securityfocus.com/bid/35838http://www.securitytracker.com/id?1022674http://www.ubuntu.com/usn/USN-831-1http://www.us-cert.gov/cas/techalerts/TA09-218A.htmlhttp://www.vupen.com/english/advisories/2009/2035http://www.vupen.com/english/advisories/2009/2172https://github.com/openexr/openexr/blob/master/CHANGES.md#version-170-july-23-2010https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.htmlhttp://lists.apple.com/archives/security-announce/2009/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-09/msg00000.htmlhttp://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiffhttp://secunia.com/advisories/36030http://secunia.com/advisories/36032http://secunia.com/advisories/36096http://secunia.com/advisories/36123http://secunia.com/advisories/36753http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gzhttp://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gzhttp://support.apple.com/kb/HT3757http://www.debian.org/security/2009/dsa-1842http://www.mandriva.com/security/advisories?name=MDVSA-2009:190http://www.mandriva.com/security/advisories?name=MDVSA-2009:191http://www.securityfocus.com/bid/35838http://www.securitytracker.com/id?1022674http://www.ubuntu.com/usn/USN-831-1http://www.us-cert.gov/cas/techalerts/TA09-218A.htmlhttp://www.vupen.com/english/advisories/2009/2035http://www.vupen.com/english/advisories/2009/2172https://github.com/openexr/openexr/blob/master/CHANGES.md#version-170-july-23-2010https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.html
2009-07-31
Published