CVE-2017-12596
Published: 07 August 2017
In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
openexr Launchpad, Ubuntu, Debian |
Upstream |
Released
(1.6.1-6+deb7u1, 2.2.0-11.1)
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(2.2.0-11.1ubuntu1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(2.2.0-10ubuntu2.1)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was needed)
|
|
Patches: Upstream: https://github.com/openexr/openexr/commit/f09f5f26c1924c4f7e183428ca79c9881afaf53c (2.3) Upstream: https://github.com/openexr/openexr/commit/49db4a4192482eec9c27669f75db144cf5434804 (2.2) |
Notes
Author | Note |
---|---|
mdeslaur | same patch as CVE-2017-9110 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12596
- https://github.com/xiaoqx/pocs/blob/master/openexr.md
- https://usn.ubuntu.com/usn/usn-4148-1
- NVD
- Launchpad
- Debian