OpenEXR to specyfikacja i referencyjna implementacja formatu pliku EXR, formatu przechowywania obrazów dla branży filmowej. W wersjach 3.3.0 do 3.3.6 i 3.4.0 do 3.4.4 występuje heap-buffer-overflow (OOB read) w funkcji `istream_nonparallel_read` w pliku `ImfContextInit.cpp` podczas przetwarzania zniekształconego pliku EXR przez memory-mapped `IStream`. Odejmowanie liczb całkowitych ze znakiem daje ujemną wartość, która jest niejawnie konwertowana na `size_t`, co powoduje przesłanie ogromnej długości do `memcpy`. Wersje 3.3.7 i 3.4.5 zawierają patch.
▸ Pokaż oryginał (EN)
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.6 and 3.4.0 through 3.4.4, a heap-buffer-overflow (OOB read) occurs in the `istream_nonparallel_read` function in `ImfContextInit.cpp` when parsing a malformed EXR file through a memory-mapped `IStream`. A signed integer subtraction produces a negative value that is implicitly converted to `size_t`, resulting in a massive length being passed to `memcpy`. Versions 3.3.7 and 3.4.5 contain a patch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HOpenexr
APPOpenexr3.3.0 – 3.3.7 (bez)3.4.0 – 3.4.5 (bez)
Powiązane podatności
Heap-based buffer overflow w bibliotece OpenEXR przy parsowaniu deep scanline
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion ...
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...