Bug 2262397 (CVE-2023-5841) - CVE-2023-5841 OpenEXR: Heap Overflow in Scanline Deep Data Parsing
Summary: CVE-2023-5841 OpenEXR: Heap Overflow in Scanline Deep Data Parsing
Keywords:
Status: NEW
Alias: CVE-2023-5841
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2262398 2262399 2262406 2262407
Blocks: 2262396
TreeView+ depends on / blocked
 
Reported: 2024-02-02 13:51 UTC by Patrick Del Bello
Modified: 2024-04-08 14:30 UTC (History)
3 users (show)

Fixed In Version: OpenEXR 3.2.1
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in the Academy Software Foundation OpenEXR and requires that a malicious EXR file image is parsed by the target device or environment using OpenEXR. This issue occurs due to a failure in validating the number of scanline samples of an OpenEXR file containing deep scanline data, allowing a read or write primitive based on the provided EXR file attributes. This flaw could be used to read or write memory to a compromised device through an attacker-placed EXR image.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2024-02-02 13:51:38 UTC
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability.

https://takeonme.org/cves/CVE-2023-5841.html

Comment 1 Patrick Del Bello 2024-02-02 13:53:31 UTC
Created openexr2 tracking bugs for this issue:

Affects: fedora-all [bug 2262399]


Created usd tracking bugs for this issue:

Affects: fedora-all [bug 2262398]

Comment 3 Mauro Matteo Cascella 2024-02-02 14:41:29 UTC
Created mingw-openexr tracking bugs for this issue:

Affects: fedora-all [bug 2262407]


Created openexr tracking bugs for this issue:

Affects: fedora-all [bug 2262406]


Note You need to log in before you can comment on or make changes to this bug.