CVE-2009-1722
published 2009-07-31CVE-2009-1722: Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.54%
90.5th percentile
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openexr | < openexr 1.6.1-1 (bookworm) | openexr 1.6.1-1 (bookworm) |
| openexr | openexr | — | — |
| openexr | openexr | >= 0 < 1.6.1-1 | 1.6.1-1 |
| openexr | openexr | >= 0 < 1.6.1-1 | 1.6.1-1 |
| openexr | openexr | >= 0 < 1.6.1-1 | 1.6.1-1 |
| openexr | openexr | >= 0 < 1.6.1-1 | 1.6.1-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenEXR vulnerabilities
vendor_ubuntu·2009-09-14·CVSS 7.5
CVE-2009-1720 [HIGH] OpenEXR vulnerabilities
Title: OpenEXR vulnerabilities
Summary: OpenEXR vulnerabilities
Drew Yao discovered several flaws in the way OpenEXR handled certain
malformed EXR image files. If a user were tricked into opening a crafted
EXR image file, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1720, CVE-2009-1721)
It was discovered that OpenEXR did not properly handle certain malformed
EXR image files. If a user were tricked into opening a crafted EXR image
file, an attacker could cause a denial of service via application crash, or
possibly execute arbitrary code with the privileges of the user invoking
the program. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-1722)
Instructions: In gene
Debian
CVE-2009-1722: openexr - Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 al...
vendor_debian·2009·CVSS 6.8
CVE-2009-1722 [MEDIUM] CVE-2009-1722: openexr - Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 al...
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
Red Hat
OpenEXR: Integer overflow in decompression of range of values in the pixel data
vendor_redhat·2007-10-22·CVSS 6.8
CVE-2009-1722 [MEDIUM] CWE-190 OpenEXR: Integer overflow in decompression of range of values in the pixel data
OpenEXR: Integer overflow in decompression of range of values in the pixel data
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
GHSA
GHSA-g7x3-mh62-h5hm: Heap-based buffer overflow in the compression implementation in OpenEXR 1
ghsa_unreviewed·2022-05-02
CVE-2009-1722 [MEDIUM] CWE-119 GHSA-g7x3-mh62-h5hm: Heap-based buffer overflow in the compression implementation in OpenEXR 1
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
OSV
CVE-2009-1722: Heap-based buffer overflow in the compression implementation in OpenEXR 1
osv·2009-07-31·CVSS 6.8
CVE-2009-1722 [MEDIUM] CVE-2009-1722: Heap-based buffer overflow in the compression implementation in OpenEXR 1
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1722 OpenEXR: Integer overflow in decompression of range of values in the pixel data
bugzilla·2009-07-27·CVSS 6.8
CVE-2009-1722 [MEDIUM] CVE-2009-1722 OpenEXR: Integer overflow in decompression of range of values in the pixel data
CVE-2009-1722 OpenEXR: Integer overflow in decompression of range of values in the pixel data
An integer overflow flaw, leading to heap-based buffer overflow was found
in the OpenEXR's routine, decompressing range of values in the pixel data.
A remote attacker provide a specially-crafted image file, which once
opened, by a local, unsuspecting user, would lead to denial of service
("exrmakepreview crash") or potentially, arbitrary code execution with
the privileges of user opening the image.
References:
http://openexr.com/
Part "Announcements"
October 22, 2007 - New versions of OpenEXR and CTL are now available. This release fixes a buffer overrun in OpenEXR and a Windows build problem in CTL, and it removes a few unnecessary files from the .tar.gz packages.
Discussion:
This issue doe
Bugzilla
CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression
bugzilla·2009-07-27·CVSS 7.5
CVE-2009-1721 [HIGH] CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression
CVE-2009-1721 OpenEXR: Invalid pointer free by image decompression
An invalid pointer free flaw was found in OpenEXR by Huffman decoding.
A remote attacker could provide a specially-crafted image file, which
once opened to a local, unsuspecting user would lead to denial of
service ("exrmakepreview" crash).
Credit: Drew Yao of Apple Product Security
Discussion:
Public now via:
http://seclists.org/fulldisclosure/2009/Jul/0444.html
---
This issue affects the versions of the OpenEXR package, as shipped
with Fedora releases of 10 and 11.
This issue affects the versions of the OpenEXR package, as shipped
with Extra Packages for Enterprise Linux 4 (EPEL4) and Extra
Packages for Enterprise Linux 5 (EPEL5) projects.
---
Created attachment 355419
Freeing unitialised pointers (CVE-2009-1721
http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.htmlhttp://secunia.com/advisories/36032http://secunia.com/advisories/36096http://secunia.com/advisories/36753http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gzhttp://support.apple.com/kb/HT3757http://www.debian.org/security/2009/dsa-1842http://www.mandriva.com/security/advisories?name=MDVSA-2009:191http://www.securityfocus.com/bid/35838http://www.securitytracker.com/id?1022674http://www.ubuntu.com/usn/USN-831-1http://www.us-cert.gov/cas/techalerts/TA09-218A.htmlhttp://www.vupen.com/english/advisories/2009/2035http://www.vupen.com/english/advisories/2009/2172https://github.com/openexr/openexr/blob/master/CHANGES.md#version-170-july-23-2010http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.htmlhttp://secunia.com/advisories/36032http://secunia.com/advisories/36096http://secunia.com/advisories/36753http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gzhttp://support.apple.com/kb/HT3757http://www.debian.org/security/2009/dsa-1842http://www.mandriva.com/security/advisories?name=MDVSA-2009:191http://www.securityfocus.com/bid/35838http://www.securitytracker.com/id?1022674http://www.ubuntu.com/usn/USN-831-1http://www.us-cert.gov/cas/techalerts/TA09-218A.htmlhttp://www.vupen.com/english/advisories/2009/2035http://www.vupen.com/english/advisories/2009/2172https://github.com/openexr/openexr/blob/master/CHANGES.md#version-170-july-23-2010
2009-07-31
Published