CVE-2009-1721
published 2009-07-31CVE-2009-1721: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.29%
90.0th percentile
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.5.8 | 10.5.8 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openexr | < openexr 1.6.1-4.1 (bookworm) | openexr 1.6.1-4.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| openexr | openexr | — | — |
| openexr | openexr | — | — |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
| openexr | openexr | >= 0 < 1.6.1-4.1 | 1.6.1-4.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenEXR vulnerabilities
vendor_ubuntu·2009-09-14·CVSS 7.5
CVE-2009-1720 [HIGH] OpenEXR vulnerabilities
Title: OpenEXR vulnerabilities
Summary: OpenEXR vulnerabilities
Drew Yao discovered several flaws in the way OpenEXR handled certain
malformed EXR image files. If a user were tricked into opening a crafted
EXR image file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1720, CVE-2009-1721)
It was discovered that OpenEXR did not properly handle certain malformed
EXR image files. If a user were tricked into opening a crafted EXR image
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-1722)
Instructions: In gene
Red Hat
OpenEXR: Invalid pointer free by image decompression
vendor_redhat·2009-07-28·CVSS 6.8
CVE-2009-1721 [MEDIUM] OpenEXR: Invalid pointer free by image decompression
OpenEXR: Invalid pointer free by image decompression
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
Debian
CVE-2009-1721: openexr - The decompression implementation in the Imf::hufUncompress function in OpenEXR 1...
vendor_debian·2009·CVSS 6.8
CVE-2009-1721 [MEDIUM] CVE-2009-1721: openexr - The decompression implementation in the Imf::hufUncompress function in OpenEXR 1...
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
Scope: local
bookworm: resolved (fixed in 1.6.1-4.1)
bullseye: resolved (fixed in 1.6.1-4.1)
forky: resolved (fixed in 1.6.1-4.1)
sid: resolved (fixed in 1.6.1-4.1)
trixie: resolved (fixed in 1.6.1-4.1)
GHSA
GHSA-wrhp-5vcr-45pg: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1
ghsa_unreviewed·2022-05-02
CVE-2009-1721 [MEDIUM] CWE-824 GHSA-wrhp-5vcr-45pg: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
OSV
CVE-2009-1721: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1
osv·2009-07-31·CVSS 6.8
CVE-2009-1721 [MEDIUM] CVE-2009-1721: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-09/msg00000.htmlhttp://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiffhttp://secunia.com/advisories/36030http://secunia.com/advisories/36032http://secunia.com/advisories/36096http://secunia.com/advisories/36123http://secunia.com/advisories/36753http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gzhttp://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gzhttp://support.apple.com/kb/HT3757http://www.debian.org/security/2009/dsa-1842http://www.mandriva.com/security/advisories?name=MDVSA-2009:190http://www.mandriva.com/security/advisories?name=MDVSA-2009:191http://www.securityfocus.com/bid/35838http://www.securitytracker.com/id?1022674http://www.ubuntu.com/usn/USN-831-1http://www.us-cert.gov/cas/techalerts/TA09-218A.htmlhttp://www.vupen.com/english/advisories/2009/2035http://www.vupen.com/english/advisories/2009/2172https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.htmlhttp://lists.apple.com/archives/security-announce/2009/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-09/msg00000.htmlhttp://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiffhttp://secunia.com/advisories/36030http://secunia.com/advisories/36032http://secunia.com/advisories/36096http://secunia.com/advisories/36123http://secunia.com/advisories/36753http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gzhttp://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gzhttp://support.apple.com/kb/HT3757http://www.debian.org/security/2009/dsa-1842http://www.mandriva.com/security/advisories?name=MDVSA-2009:190http://www.mandriva.com/security/advisories?name=MDVSA-2009:191http://www.securityfocus.com/bid/35838http://www.securitytracker.com/id?1022674http://www.ubuntu.com/usn/USN-831-1http://www.us-cert.gov/cas/techalerts/TA09-218A.htmlhttp://www.vupen.com/english/advisories/2009/2035http://www.vupen.com/english/advisories/2009/2172https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.html
2009-07-31
Published