REDHAT-BUG-2467623: Integer Overflow
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.2.9 - Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.3.11 - Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.4.11
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2467623?
The severity of REDHAT-BUG-2467623 is high, rated at 7.
How do I fix REDHAT-BUG-2467623?
To fix REDHAT-BUG-2467623, upgrade OpenEXR to versions 3.2.9, 3.3.11, or 3.4.11 or later.
What is the impact of REDHAT-BUG-2467623?
The impact of REDHAT-BUG-2467623 includes potential exploitation through integer overflow in the ImageChannel::resize function.
Which versions of OpenEXR are affected by REDHAT-BUG-2467623?
OpenEXR versions from 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11 are affected by REDHAT-BUG-2467623.
What is the nature of the vulnerability in REDHAT-BUG-2467623?
REDHAT-BUG-2467623 is an integer overflow vulnerability in the OpenEXR image storage format.