Integer overflow in OpenEXR - CVE-2024-31047
Published: July 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow within the convert() function in /bin/exrmultipart/exrmultipart.cpp. A remote attacker can pass specially crafted file to the application, trigger an integer overflow and perform a denial of service (DoS) attack.
Affected software
openEuler
OpenEXR
OpenEXR-debugsource
OpenEXR-debuginfo
OpenEXR-devel
OpenEXR-libs
How to mitigate CVE-2024-31047
OpenEXR - addressed in versions 2.2.0-29, 3.1.5-3
OpenEXR-debugsource - addressed in versions 2.2.0-29, 3.1.5-3
OpenEXR-debuginfo - addressed in versions 2.2.0-29, 3.1.5-3
OpenEXR-devel - addressed in versions 2.2.0-29, 3.1.5-3
OpenEXR-libs - addressed in versions 2.2.0-29, 3.1.5-3