Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2023-5841: OpenEXR library can overflow memory with crafted images
CVE-2023-5841 · published 2 years ago
Summary
The OpenEXR image parsing library used in Debian's openexr packages can write past its allocated memory when it processes specially crafted deep scanline files. This could cause the program to crash or be taken over by an attacker. Upgrade to library version 3.2.2 or later (or 3.1.12 for the older branch) to fix the issue.
What to do
- Update debian rootio-openexr to version 3.1.5-5.root.io.6.
- Update debian rootio-openexr to version 3.1.5-5.root.io.15.
- Update debian rootio-openexr to version 3.1.5-5.root.io.16.
- Update debian rootio-openexr to version 3.1.5-5.root.io.20.
- Update debian openexr to version 3.1.5-5.aikido.25.
- Update debian rootio-openexr to version 3.1.5-5.aikido.25.
- Update debian openexr to version 3.1.13-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:12 | debian | rootio-openexr |
< 3.1.5-5.root.io.6 < 3.1.5-5.root.io.15 < 3.1.5-5.root.io.16 < 3.1.5-5.root.io.20 < 3.1.5-5.aikido.25 Fix: upgrade to 3.1.5-5.root.io.6
|
| Root:Debian:12 | debian | openexr |
< 3.1.5-5.aikido.25 Fix: upgrade to 3.1.5-5.aikido.25
|
| Debian:12 | debian | openexr | All versions |
| Debian:13 | debian | openexr |
< 3.1.13-1 Fix: upgrade to 3.1.13-1
|
Original advisory text
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is su...
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
References
- https://security-tracker.debian.org/tracker/CVE-2023-5841 Vendor Advisory
Severity
9.1
Critical
Exploitation
EPSS 1%
Timeline
Published1 Feb 2024
Updated22 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta