CVE-2025-48071

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operation when decompressing ZIPS-packed deep scan-line EXR files with a maliciously forged chunk header. This is fixed in version 3.3.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*

History

13 Aug 2025, 19:18

Type Values Removed Values Added
CPE cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
First Time Openexr
Openexr openexr
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://github.com/AcademySoftwareFoundation/openexr/commit/916cc729e24aa16b86d82813f6e136340ab2876f - () https://github.com/AcademySoftwareFoundation/openexr/commit/916cc729e24aa16b86d82813f6e136340ab2876f - Patch
References () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.3 - () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.3 - Release Notes
References () https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-h45x-qhg2-q375 - () https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-h45x-qhg2-q375 - Exploit, Vendor Advisory

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) OpenEXR proporciona la especificación y la implementación de referencia del formato de archivo EXR, un formato de almacenamiento de imágenes para la industria cinematográfica. En las versiones 3.3.2 a 3.3.0, se produce un desbordamiento de búfer en el montón durante una operación de escritura al descomprimir archivos EXR de línea de escaneo profundo comprimidos en ZIPS con un encabezado de fragmento falsificado maliciosamente. Esto se solucionó en la versión 3.3.3.

31 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-31 21:15

Updated : 2025-08-13 19:18


NVD link : CVE-2025-48071

Mitre link : CVE-2025-48071

CVE.ORG link : CVE-2025-48071


JSON object : View

Products Affected

openexr

  • openexr
CWE
CWE-122

Heap-based Buffer Overflow