CVE-2023-5841

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*

History

26 Feb 2024, 16:27

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSB6DB5LAKGPLRXEF5HDNGUMT7GIFT2C/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWMINVKQLSUHECXBSQMZFCSDRIHFOJJI/ -

22 Feb 2024, 00:15

Type Values Removed Values Added
Summary (en) Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. (en) Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

09 Feb 2024, 20:19

Type Values Removed Values Added
First Time Openexr openexr
Openexr
CPE cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Summary
  • (es) Debido a un fallo en la validación del número de muestras de líneas de escaneo de un archivo OpenEXR que contiene datos de líneas de escaneo profundas, la librería de análisis de imágenes Academy Software Foundation OpenEX versión 3.2.1 y anteriores es susceptible a una vulnerabilidad de desbordamiento de búfer en la región Heap de la memoria.
CWE CWE-787
References () https://takeonme.org/cves/CVE-2023-5841.html - () https://takeonme.org/cves/CVE-2023-5841.html - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

01 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-01 19:15

Updated : 2024-02-26 16:27


NVD link : CVE-2023-5841

Mitre link : CVE-2023-5841

CVE.ORG link : CVE-2023-5841


JSON object : View

Products Affected

openexr

  • openexr
CWE
CWE-787

Out-of-bounds Write

CWE-122

Heap-based Buffer Overflow