CVE Vulnerabilities

CVE-2009-1720

Published: Jul 31, 2009 | Modified: Oct 23, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.

Affected Software

Name Vendor Start Version End Version
Openexr Openexr 1.2.2 (including) 1.2.2 (including)
Openexr Openexr 1.6.1 (including) 1.6.1 (including)

References