漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow
Vulnerability Description
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
Academy Software Foundation OpenEXR 缓冲区错误漏洞
Vulnerability Description
Academy Software Foundation OpenEXR是美国Academy Software Foundation基金会开源的一种高动态范围图像(HDR)文件格式的开放标准。 Academy Software Foundation OpenEXR 3.2.10及之前版本、3.3.0至3.3.12版本和3.4.0至3.4.13版本存在缓冲区错误漏洞,该漏洞源于OpenEXRUtil库的SampleCountChannel::row() API在深图像dataWindow原点非零时返回越界指针
CVSS Information
N/A
Vulnerability Type
N/A