CVE-2009-1721
31.07.2009, 19:00
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.Enginsight
Vendor | Product | Version |
---|---|---|
openexr | openexr | 1.2.2 |
openexr | openexr | 1.6.1 |
opensuse | opensuse | 10.0 |
opensuse | opensuse | 10.3 |
opensuse | opensuse | 11.0 |
apple | mac_os_x | 𝑥 < 10.5.8 |
debian | debian_linux | 4.0 |
debian | debian_linux | 5.0 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References