CVE-2023-5841
published 2024-02-01CVE-2023-5841: Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing…
PriorityP350critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.26%
66.3th percentile
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| academy_software_foundation | openexr | <= 3.2.1 | — |
| apple | ios_18_and_ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | tvos | — | — |
| apple | visionos2 | — | — |
| debian | openexr | < openexr 3.1.13-1 (forky) | openexr 3.1.13-1 (forky) |
| openexr | openexr | <= 3.2.1 | — |
| openexr | openexr | >= 0 < 3.1.13-1 | 3.1.13-1 |
| openexr | openexr | >= 0 < 3.1.13-1 | 3.1.13-1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-5841: tvOS 18
vendor_apple·2024-09-16·CVSS 9.1
CVE-2023-5841 [CRITICAL] CVE-2023-5841: tvOS 18
Apple Security Update: About the security content of tvOS 18
Product: tvOS
Version: 18
CVE: CVE-2023-5841
Component: CVE-2023-5841
Apple
CVE-2023-5841: iOS 18 and iPadOS 18
vendor_apple·2024-09-16·CVSS 9.1
CVE-2023-5841 [CRITICAL] CVE-2023-5841: iOS 18 and iPadOS 18
Apple Security Update: About the security content of iOS 18 and iPadOS 18
Product: iOS 18 and iPadOS
Version: 18
CVE: CVE-2023-5841
Component: CVE-2023-5841
Apple
CVE-2023-5841: macOS Sequoia 15
vendor_apple·2024-09-16·CVSS 9.1
CVE-2023-5841 [CRITICAL] CVE-2023-5841: macOS Sequoia 15
Apple Security Update: About the security content of macOS Sequoia 15
Product: macOS Sequoia
Version: 15
CVE: CVE-2023-5841
Component: CVE-2023-5841
Apple
CVE-2023-5841: visionOS2
vendor_apple·2024-09-16·CVSS 9.1
CVE-2023-5841 [CRITICAL] CVE-2023-5841: visionOS2
Apple Security Update: About the security content of visionOS2
Product: visionOS2
CVE: CVE-2023-5841
Component: CVE-2023-5841
Red Hat
OpenEXR: Heap Overflow in Scanline Deep Data Parsing
vendor_redhat·2024-02-01·CVSS 9.1
CVE-2023-5841 [CRITICAL] CWE-122 OpenEXR: Heap Overflow in Scanline Deep Data Parsing
OpenEXR: Heap Overflow in Scanline Deep Data Parsing
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
A vulnerability was found in the Academy Software Foundation OpenEXR and requires that a malicious EXR file image is parsed by the target device or environment using OpenEXR. This issue occurs due to a failure in validating the number of scanline samples of an OpenEXR file containing deep scanline data, allowing a read or write primitive based on the provided EXR file attributes. This flaw could be used t
Debian
CVE-2023-5841: openexr - Due to a failure in validating the number of scanline samples of a OpenEXR file ...
vendor_debian·2023·CVSS 9.1
CVE-2023-5841 [CRITICAL] CVE-2023-5841: openexr - Due to a failure in validating the number of scanline samples of a OpenEXR file ...
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 3.1.13-1)
sid: resolved (fixed in 3.1.13-1)
trixie: resolved (fixed in 3.1.13-1)
OSV
CVE-2023-5841: Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX imag
osv·2024-02-01·CVSS 9.1
CVE-2023-5841 [CRITICAL] CVE-2023-5841: Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX imag
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
GHSA
GHSA-gxmr-rxpv-c8fq: Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX imag
ghsa_unreviewed·2024-02-01
CVE-2023-5841 [CRITICAL] CWE-122 GHSA-gxmr-rxpv-c8fq: Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX imag
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/LSB6DB5LAKGPLRXEF5HDNGUMT7GIFT2C/https://lists.fedoraproject.org/archives/list/[email protected]/message/XWMINVKQLSUHECXBSQMZFCSDRIHFOJJI/https://takeonme.org/cves/CVE-2023-5841.htmlhttp://seclists.org/fulldisclosure/2024/Sep/32http://seclists.org/fulldisclosure/2024/Sep/34http://seclists.org/fulldisclosure/2024/Sep/36https://lists.fedoraproject.org/archives/list/[email protected]/message/LSB6DB5LAKGPLRXEF5HDNGUMT7GIFT2C/https://lists.fedoraproject.org/archives/list/[email protected]/message/XWMINVKQLSUHECXBSQMZFCSDRIHFOJJI/https://takeonme.org/cves/CVE-2023-5841.html
2024-02-01
Published