CVE-2017-9111
Debian Security Advisory 4755-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code.
En OpenEXR 2.2.0 una escritura inválida de tamaño 8 en la función storeSSE en ImfOptimizedPixelReading.h podría provocar el cierre inesperado de una aplicación o ejecutar código arbitrario.
Brandon Perry discovered that OpenEXR incorrectly handled certain malformed EXR image files. If a user were tricked into opening a crafted EXR image file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 20.04 LTS. Tan Jie discovered that OpenEXR incorrectly handled certain malformed EXR image files. If a user were tricked into opening a crafted EXR image file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 20.04 LTS. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-05-21 CVE Reserved
- 2017-05-21 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2017/05/12/5 | Third Party Advisory |
|
https://github.com/openexr/openexr/issues/232 | X_refsource_confirm | |
https://github.com/openexr/openexr/pull/233 | X_refsource_confirm | |
https://github.com/openexr/openexr/releases/tag/v2.2.1 | X_refsource_confirm | |
https://lists.debian.org/debian-lts-announce/2020/08/msg00056.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00060.html | 2020-08-30 | |
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00000.html | 2020-08-30 | |
https://usn.ubuntu.com/4148-1 | 2020-08-30 | |
https://usn.ubuntu.com/4339-1 | 2020-08-30 | |
https://www.debian.org/security/2020/dsa-4755 | 2020-08-30 |