Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2023-5841: OpenEXR library can overflow memory with crafted images

CVE-2023-5841 · published 2 years ago
Summary

The OpenEXR image parsing library used in Debian's openexr packages can write past its allocated memory when it processes specially crafted deep scanline files. This could cause the program to crash or be taken over by an attacker. Upgrade to library version 3.2.2 or later (or 3.1.12 for the older branch) to fix the issue.

What to do
  • Update debian rootio-openexr to version 3.1.5-5.root.io.6.
  • Update debian rootio-openexr to version 3.1.5-5.root.io.15.
  • Update debian rootio-openexr to version 3.1.5-5.root.io.16.
  • Update debian rootio-openexr to version 3.1.5-5.root.io.20.
  • Update debian openexr to version 3.1.5-5.aikido.25.
  • Update debian rootio-openexr to version 3.1.5-5.aikido.25.
  • Update debian openexr to version 3.1.13-1.
Affected software
Ecosystem VendorProductAffected versions
Root:Debian:12 debian rootio-openexr < 3.1.5-5.root.io.6
< 3.1.5-5.root.io.15
< 3.1.5-5.root.io.16
< 3.1.5-5.root.io.20
< 3.1.5-5.aikido.25
Fix: upgrade to 3.1.5-5.root.io.6
Root:Debian:12 debian openexr < 3.1.5-5.aikido.25
Fix: upgrade to 3.1.5-5.aikido.25
Debian:12 debian openexr All versions
Debian:13 debian openexr < 3.1.13-1
Fix: upgrade to 3.1.13-1
Original advisory text
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is su...
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
Severity
9.1 Critical
Exploitation
EPSS 1%
Timeline
Published1 Feb 2024
Updated22 Sep 2026
First seen6 Mar 2026
Sources
CVE-2023-5841 · NVD
Track software like this
Free during beta