Medium severity5.5NVD Advisory· Published Oct 3, 2017· Updated May 13, 2026
CVE-2017-14988
CVE-2017-14988
Description
Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputFile function in IlmImf/ImfCRgbaFile.cpp. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/openexr/openexr/issues/248nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00063.htmlnvd
News mentions
0No linked articles in our index yet.