Description
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operation when decompressing ZIPS-packed deep scan-line EXR files with a maliciously forged chunk header. This is fixed in version 3.3.3.
Problem types
CWE-122: Heap-based Buffer Overflow
Product status
References
github.com/...penexr/security/advisories/GHSA-h45x-qhg2-q375
github.com/...ommit/916cc729e24aa16b86d82813f6e136340ab2876f
github.com/...SoftwareFoundation/openexr/releases/tag/v3.3.3