CVE-2025-48072 Information
Aug 01, 2025
cve
Description
OpenEXR provides the specification and reference implementation of the EXR file format an image storage format for the motion picture industry. Version 3.3.2 is vulnerable to a heap-based buffer overflow during a read operation due to bad pointer math when decompressing DWAA-packed scan-line EXR files with a maliciously forged chunk. This is fixed in version 3.3.3.
Reference
https://github.com/AcademySoftwareFoundation/openexr/commit/2d09449427b13a05f7c31a98ab2c4347c23db361 https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.3 https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-4r7w-q3jg-ff43
Related CNNVD
CNNVD-202507-3958 (Published: 2025-07-31)
Share on: