OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.
Metrics
Affected Vendors & Products
References
History
Sat, 02 Aug 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Fri, 01 Aug 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3. | |
Title | OpenEXR's Unbounded File Header Values can Lead to Out-Of-Memory Errors | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-01T16:32:54.595Z
Updated: 2025-08-01T17:09:00.696Z
Reserved: 2025-05-15T16:06:40.942Z
Link: CVE-2025-48074

Updated: 2025-08-01T17:08:51.656Z

Status : Awaiting Analysis
Published: 2025-08-01T17:15:52.193
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-48074
