Critical severity9.1NVD Advisory· Published Feb 1, 2024· Updated Jun 17, 2026
CVE-2023-5841
CVE-2023-5841
Description
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Range: <=3.2.1, >=3.1.12
- osv-coords3 versions
< 3.1.1-2.el9_4.1+ 2 more
- (no CPE)range: < 3.1.1-2.el9_4.1
- (no CPE)range: < 3.1.1-2.el9_4.1
- (no CPE)range: < 3.1.1-2.el9_4.1
- Range: 0
Patches
Vulnerability mechanics
References
6- takeonme.org/cves/CVE-2023-5841.htmlnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2024/Sep/32nvd
- seclists.org/fulldisclosure/2024/Sep/34nvd
- seclists.org/fulldisclosure/2024/Sep/36nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/LSB6DB5LAKGPLRXEF5HDNGUMT7GIFT2C/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/XWMINVKQLSUHECXBSQMZFCSDRIHFOJJI/nvd
News mentions
0No linked articles in our index yet.