Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45889
HistoryMar 17, 2024 - 3:29 p.m.

Out-of-bounds Write

2024-03-1715:29:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
openexr
vulnerability
patch
scanline
data
validation

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

28.8%

openexr is vulnerable to due Out-of-bounds Write. The vulnerability is due to a failure in validating the number of scanline samples of an OpenEXR file containing deep scanline data. This vulnerability was addressed in versions v3.2.2 and v3.1.12 of the affected library.

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

28.8%