CVE Vulnerabilities

CVE-2009-1720

Published: Jul 31, 2009 | Modified: Oct 23, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.

Affected Software

Name Vendor Start Version End Version
Openexr Openexr 1.2.2 (including) 1.2.2 (including)
Openexr Openexr 1.6.1 (including) 1.6.1 (including)
Openexr Ubuntu dapper *
Openexr Ubuntu devel *
Openexr Ubuntu hardy *
Openexr Ubuntu intrepid *
Openexr Ubuntu jaunty *

References