Debian Openexr vulnerabilities
57 known vulnerabilities affecting debian/openexr.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM39LOW7
Vulnerabilities
Page 2 of 3
CVE-2021-20296P4MEDIUMCVSS 5.3fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20296 [MEDIUM] CVE-2021-20296: openexr - A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file ...
A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: reso
debian
CVE-2021-3475P4MEDIUMCVSS 5.3fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3475 [MEDIUM] CVE-2021-3475: openexr - There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can su...
There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: resolved (fixed in 2.5.4-1)
forky: resolved (fixed in 2.5.4-1)
sid: resolved (fixed
debian
CVE-2021-45942P4MEDIUMCVSS 5.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-45942 [MEDIUM] CVE-2021-45942: openexr - OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineComp...
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
Scope: local
bookworm: resolved (fixed in 3.1.5-2)
bullseye: resolved (fixed in 2.5.4-2+deb11u1)
forky: resolved (fixed in 3.
debian
CVE-2021-3941P4MEDIUMCVSS 6.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-3941 [MEDIUM] CVE-2021-3941: openexr - In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations ...
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked wit
debian
CVE-2017-9116P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9116 [MEDIUM] CVE-2017-9116: openexr - In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip...
In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip.cpp could cause the application to crash.
Scope: local
bookworm: resolved (fixed in 2.2.0-11.1)
bullseye: resolved (fixed in 2.2.0-11.1)
forky: resolved (fixed in 2.2.0-11.1)
sid: resolved (fixed in 2.2.0-11.1)
trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2017-9112P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9112 [MEDIUM] CVE-2017-9112: openexr - In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cp...
In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cpp could cause the application to crash.
Scope: local
bookworm: resolved (fixed in 2.2.0-11.1)
bullseye: resolved (fixed in 2.2.0-11.1)
forky: resolved (fixed in 2.2.0-11.1)
sid: resolved (fixed in 2.2.0-11.1)
trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2021-20303P4MEDIUMCVSS 6.1fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20303 [MEDIUM] CVE-2021-20303: openexr - A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An atta...
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to application availability, with some potential impact to data integrity as well.
Scope: local
boo
debian
CVE-2020-11759P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11759 [MEDIUM] CVE-2020-11759: openexr - An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in...
An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.
debian
CVE-2017-9114P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9114 [MEDIUM] CVE-2017-9114: openexr - In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf...
In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf.cpp could cause the application to crash.
Scope: local
bookworm: resolved (fixed in 2.2.0-11.1)
bullseye: resolved (fixed in 2.2.0-11.1)
forky: resolved (fixed in 2.2.0-11.1)
sid: resolved (fixed in 2.2.0-11.1)
trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2017-9110P4MEDIUMCVSS 6.5fixed in openexr 2.2.0-11.1 (bookworm)2017
CVE-2017-9110 [MEDIUM] CVE-2017-9110: openexr - In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf....
In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash.
Scope: local
bookworm: resolved (fixed in 2.2.0-11.1)
bullseye: resolved (fixed in 2.2.0-11.1)
forky: resolved (fixed in 2.2.0-11.1)
sid: resolved (fixed in 2.2.0-11.1)
trixie: resolved (fixed in 2.2.0-11.1)
debian
CVE-2020-11764P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11764 [MEDIUM] CVE-2020-11764: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write...
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-11762P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11762 [MEDIUM] CVE-2020-11762: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ...
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixe
debian
CVE-2020-11763P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11763 [MEDIUM] CVE-2020-11763: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-...
An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2021-3479P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3479 [MEDIUM] CVE-2021-3479: openexr - There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-...
There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption of memory, resulting in an impact to system availability.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: resolved (fixed in 2.5.4-1)
forky: resolved (fixed
debian
CVE-2020-11760P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11760 [MEDIUM] CVE-2020-11760: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ...
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-11758P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11758 [MEDIUM] CVE-2020-11758: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ...
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-11761P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11761 [MEDIUM] CVE-2020-11761: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read ...
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2020-16587P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-16587 [MEDIUM] CVE-2020-16587: openexr - A heap-based buffer overflow vulnerability exists in Academy Software Foundation...
A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp that can cause a denial of service via a crafted EXR file.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-
debian
CVE-2021-3477P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3477 [MEDIUM] CVE-2021-3477: openexr - There's a flaw in OpenEXR's deep tile sample size calculations in versions befor...
There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, subsequently leading to an out-of-bounds read. The greatest risk of this flaw is to application availability.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bu
debian
CVE-2021-3478P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-3478 [MEDIUM] CVE-2021-3478: openexr - There's a flaw in OpenEXR's scanline input file functionality in versions before...
There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory. The greatest impact of this flaw is to system availability.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: resolved (fixed in 2.5.4-1)
forky: resolved (f
debian