Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 627226 (CVE-2017-12596) - <media-libs/openexr-2.3.0: denial of service in hufDecode function (CVE-2017-12596)
Summary: <media-libs/openexr-2.3.0: denial of service in hufDecode function (CVE-2017-...
Status: RESOLVED FIXED
Alias: CVE-2017-12596
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on: CVE-2017-9110, CVE-2017-9111, CVE-2017-9112, CVE-2017-9113, CVE-2017-9114, CVE-2017-9115, CVE-2017-9116
Blocks:
  Show dependency tree
 
Reported: 2017-08-07 08:04 UTC by Aleksandr Wagner (Kivak)
Modified: 2019-08-02 00:16 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-08-07 08:04:01 UTC
CVE-2017-12596 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12596):

In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact. 

References:

https://github.com/openexr/openexr/issues/238
https://github.com/xiaoqx/pocs/blob/master/openexr.md