MEDIUM · 6.8

CVE-2009-1721

The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute a...

Vulnerability Description

The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OpenexrOpenexr1.2.2
OpensuseOpensuse10.0
AppleMac Os X< 10.5.8
DebianDebian Linux4.0
CanonicalUbuntu Linux8.04
FedoraprojectFedora10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-1721?

CVE-2009-1721 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute a...

How severe is CVE-2009-1721?

CVE-2009-1721 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-1721?

Check the references section above for vendor advisories and patch information. Affected products include: Openexr Openexr, Opensuse Opensuse, Apple Mac Os X, Debian Debian Linux, Canonical Ubuntu Linux.