cbcvebase.

Debian Openexr vulnerabilities

57 known vulnerabilities affecting debian/openexr.

Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM39LOW7

Vulnerabilities

Page 2 of 3
CVE-2021-20296P4MEDIUMCVSS 5.3fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20296 [MEDIUM] CVE-2021-20296: openexr - A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file ... A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.5.4-1) bullseye: reso
debian
CVE-2021-3475P4MEDIUMCVSS 5.3fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3475 [MEDIUM] CVE-2021-3475: openexr - There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can su... There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability. Scope: local bookworm: resolved (fixed in 2.5.4-1) bullseye: resolved (fixed in 2.5.4-1) forky: resolved (fixed in 2.5.4-1) sid: resolved (fixed
debian
CVE-2021-45942P4MEDIUMCVSS 5.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-45942 [MEDIUM] CVE-2021-45942: openexr - OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineComp... OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable. Scope: local bookworm: resolved (fixed in 3.1.5-2) bullseye: resolved (fixed in 2.5.4-2+deb11u1) forky: resolved (fixed in 3.
debian
CVE-2021-3941P4MEDIUMCVSS 6.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-3941 [MEDIUM] CVE-2021-3941: openexr - In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations ... In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked wit
debian
CVE-2017-9116P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9116 [MEDIUM] CVE-2017-9116: openexr - In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip... In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip.cpp could cause the application to crash. Scope: local bookworm: resolved (fixed in 2.2.0-11.1) bullseye: resolved (fixed in 2.2.0-11.1) forky: resolved (fixed in 2.2.0-11.1) sid: resolved (fixed in 2.2.0-11.1) trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2017-9112P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9112 [MEDIUM] CVE-2017-9112: openexr - In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cp... In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cpp could cause the application to crash. Scope: local bookworm: resolved (fixed in 2.2.0-11.1) bullseye: resolved (fixed in 2.2.0-11.1) forky: resolved (fixed in 2.2.0-11.1) sid: resolved (fixed in 2.2.0-11.1) trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2021-20303P4MEDIUMCVSS 6.1fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20303 [MEDIUM] CVE-2021-20303: openexr - A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An atta... A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well. Scope: local boo
debian
CVE-2020-11759P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11759 [MEDIUM] CVE-2020-11759: openexr - An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in... An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.
debian
CVE-2017-9114P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9114 [MEDIUM] CVE-2017-9114: openexr - In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf... In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf.cpp could cause the application to crash. Scope: local bookworm: resolved (fixed in 2.2.0-11.1) bullseye: resolved (fixed in 2.2.0-11.1) forky: resolved (fixed in 2.2.0-11.1) sid: resolved (fixed in 2.2.0-11.1) trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2017-9110P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9110 [MEDIUM] CVE-2017-9110: openexr - In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.... In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash. Scope: local bookworm: resolved (fixed in 2.2.0-11.1) bullseye: resolved (fixed in 2.2.0-11.1) forky: resolved (fixed in 2.2.0-11.1) sid: resolved (fixed in 2.2.0-11.1) trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2020-11764P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11764 [MEDIUM] CVE-2020-11764: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write... An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-11762P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11762 [MEDIUM] CVE-2020-11762: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ... An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixe
debian
CVE-2020-11763P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11763 [MEDIUM] CVE-2020-11763: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-... An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2021-3479P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3479 [MEDIUM] CVE-2021-3479: openexr - There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-... There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availability. Scope: local bookworm: resolved (fixed in 2.5.4-1) bullseye: resolved (fixed in 2.5.4-1) forky: resolved (fixed
debian
CVE-2020-11760P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11760 [MEDIUM] CVE-2020-11760: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ... An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-11758P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11758 [MEDIUM] CVE-2020-11758: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ... An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-11761P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11761 [MEDIUM] CVE-2020-11761: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ... An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-16587P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-16587 [MEDIUM] CVE-2020-16587: openexr - A heap-based buffer overflow vulnerability exists in Academy Software Foundation... A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp that can cause a denial of service via a crafted EXR file. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-
debian
CVE-2021-3477P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3477 [MEDIUM] CVE-2021-3477: openexr - There's a flaw in OpenEXR's deep tile sample size calculations in versions befor... There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read. The greatest risk of this flaw is to application availability. Scope: local bookworm: resolved (fixed in 2.5.4-1) bu
debian
CVE-2021-3478P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3478 [MEDIUM] CVE-2021-3478: openexr - There's a flaw in OpenEXR's scanline input file functionality in versions before... There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availability. Scope: local bookworm: resolved (fixed in 2.5.4-1) bullseye: resolved (fixed in 2.5.4-1) forky: resolved (f
debian
Debian Openexr vulnerabilities | cvebase