CVE-2017-9114Out-of-bounds Read in Openexr

CWE-125Out-of-bounds Read8 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
1.0%
top 23.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 21
Latest updateMay 13

Description

In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf.cpp could cause the application to crash.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/openexr< openexr 2.2.0-11.1 (bookworm)
Debianopenexr/openexr< 2.2.0-11.1+3
NVDopenexr/openexr2.2.0

🔴Vulnerability Details

2
GHSA
GHSA-fqq4-jr8p-g7pr: In OpenEXR 22022-05-13
OSV
CVE-2017-9114: In OpenEXR 22017-05-21

📋Vendor Advisories

2
Red Hat
OpenEXR: Out-of-bounds read in the refill function2017-05-12
Debian
CVE-2017-9114: openexr - In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf...2017

💬Community

3
Bugzilla
CVE-2017-9114 OpenEXR: Out-of-bounds read in the refill function2017-05-25
Bugzilla
CVE-2017-9110 CVE-2017-9111 CVE-2017-9112 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9116 OpenEXR: various flaws [fedora-all]2017-05-25
Bugzilla
CVE-2017-9110 CVE-2017-9111 CVE-2017-9112 CVE-2017-9113 CVE-2017-9114 CVE-2017-9115 CVE-2017-9116 mingw-OpenEXR: various flaws [fedora-all]2017-05-25