Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1110261: openexr: CVE-2025-48074

    From Salvatore Bonaccorso@21:1/5 to All on Sat Aug 2 13:10:02 2025
    Source: openexr
    Version: 3.1.13-2
    Severity: important
    Tags: security upstream
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

    Hi,

    The following vulnerability was published for openexr.

    CVE-2025-48074[0]:
    | OpenEXR provides the specification and reference implementation of
    | the EXR file format, an image storage format for the motion picture
    | industry. In version 3.3.2, applications trust unvalidated
    | dataWindow size values from file headers, which can lead to
    | excessive memory allocation and performance degradation when
    | processing malicious files. This is fixed in version 3.3.3.

    While the advisory explicitly mentions only 3.3.2, by code inspection
    I have not seen a reason why this should only ever have been
    introduced in 3.3.2 and actually affect older versions (generally
    anyway not trusting a CVE description as they reflect only e.g.
    assessment in a given point in time).

    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-48074
    https://www.cve.org/CVERecord?id=CVE-2025-48074
    [1] https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-x22w-82jp-8rvf
    [2] https://github.com/AcademySoftwareFoundation/openexr/commit/501be087faa62d0fb7115ce3a0ebd7b4ef0117fc

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon Jun 8 08:26:26 2026
      from Wales, Uk via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 43:00:35
    Calls: 12,110
    Calls today: 1
    Files: 15,008
    Messages: 6,518,438

© >>> Magnum BBS <<<, 2026