Heap-based buffer overflow in OpenEXR - CVE-2023-5841
Published: February 7, 2024 / Updated: February 15, 2024
OpenEXR
Amazon Linux AMI
visionOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
tvOS
openEuler
Anolis OS
Fedora
macOS
iPadOS
Apple iOS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
OpenEXR (Red Hat package)
openexr
OpenEXR-debuginfo
OpenEXR-libs
OpenEXR-devel
OpenEXR-debugsource
OpenEXR
OpenEXR-doc
mingw-openexr
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when validating the number of scanline samples of a OpenEXR file containing deep scanline data. A remote attacker can pass specially crafted file to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.