Out-of-bounds write in OpenEXR - CVE-2018-18444
Published: August 19, 2019
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the exrmultiview in makeMultiView.cpp. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger out-of-bounds write and execute arbitrary code on the target system.
Affected software
openexr (Ubuntu package)
openexr (Alpine package)
mingw-openexr
mingw-ilmbase
Opensuse
Fedora
How to mitigate CVE-2018-18444
openexr (Alpine package) - update to 2.2.1-r1
mingw-openexr - addressed in versions 2.2.1-5.fc30, 2.3.0-3.fc31
mingw-ilmbase - update to 2.3.0-3.fc31