← Back

CVE-2023-5841

nvd nist
Published: Feb 1, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

Affected (1)

Products: Openexr: Openexr
1 product
Openexr
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.2.1

Timeline

No history available yet.