Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28453
HistoryDec 06, 2020 - 4:40 a.m.

Denial Of Service (DoS)

2020-12-0604:40:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
openexr
vulnerability
dwacompressor::uncompress
imfdwacompressor.cpp
out-of-bounds read
out-of-bounds write
unknown compression
application crash

EPSS

0.001

Percentile

41.3%

openexr is vulnerable to denial of service (DoS). The vulnerability exists in the DwaCompressor::uncompress in ImfDwaCompressor.cpp due to the out-of-bounds read and write when handling the UNKNOWN compression, allowing an attacker to crash the application.