The vendor explicitly identifies these products as affected by this CVE.
- OpenEXR-devel as a component of Red Hat Enterprise Linux 6
- OpenEXR-libs as a component of Red Hat Enterprise Linux 6
- OpenEXR.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in OpenEXR, an image storage format library for the motion picture industry. An attacker can craft a malicious EXR file that, when processed, causes an integer overflow in the `CompositeDeepScanLine::readPixels` function. This overflow leads to an undersized buffer allocation, which can then be overrun during write operations. Successful exploitation could result in arbitrary code execution or a denial of service (DoS).
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
