Unrated severityNVD Advisory· Published Jul 31, 2009· Updated Apr 23, 2026
CVE-2009-1721
CVE-2009-1721
Description
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
Affected products
13cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiffnvdBroken LinkPatch
- security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gznvdBroken LinkPatch
- security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gznvdBroken LinkPatch
- www.securityfocus.com/bid/35838nvdBroken LinkPatchThird Party AdvisoryVDB Entry
- secunia.com/advisories/36030nvdBroken LinkVendor Advisory
- secunia.com/advisories/36032nvdBroken LinkVendor Advisory
- support.apple.com/kb/HT3757nvdThird Party Advisory
- www.securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-831-1nvdThird Party Advisory
- www.us-cert.gov/cas/techalerts/TA09-218A.htmlnvdThird Party AdvisoryUS Government Resource
- www.vupen.com/english/advisories/2009/2035nvdBroken LinkVendor Advisory
- lists.apple.com/archives/security-announce/2009/Aug/msg00001.htmlnvdMailing List
- lists.opensuse.org/opensuse-security-announce/2009-09/msg00000.htmlnvdMailing List
- secunia.com/advisories/36096nvdBroken Link
- secunia.com/advisories/36123nvdBroken Link
- secunia.com/advisories/36753nvdBroken Link
- www.debian.org/security/2009/dsa-1842nvdMailing List
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.vupen.com/english/advisories/2009/2172nvdBroken Link
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.htmlnvdMailing List
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.htmlnvdMailing List
News mentions
0No linked articles in our index yet.