OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.
References
Link | Resource |
---|---|
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-x22w-82jp-8rvf | Exploit Vendor Advisory |
https://github.com/ShielderSec/poc/tree/main/CVE-2025-48074 | Exploit |
Configurations
History
13 Aug 2025, 19:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-x22w-82jp-8rvf - Exploit, Vendor Advisory | |
References | () https://github.com/ShielderSec/poc/tree/main/CVE-2025-48074 - Exploit | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CPE | cpe:2.3:a:openexr:openexr:3.3.2:*:*:*:*:*:*:* | |
First Time |
Openexr
Openexr openexr |
04 Aug 2025, 15:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-01 17:15
Updated : 2025-08-13 19:18
NVD link : CVE-2025-48074
Mitre link : CVE-2025-48074
CVE.ORG link : CVE-2025-48074
JSON object : View
Products Affected
openexr
- openexr
CWE
CWE-770
Allocation of Resources Without Limits or Throttling