Vulnerability Name:
CVE-2009-1722 (CCN-52069)
Assigned:
2009-07-28
Published:
2009-07-28
Updated:
2012-10-23
Summary:
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
CVSS v3 Severity:
7.3 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
Low
Availibility (A):
Low
CVSS v2 Severity:
6.8 Medium
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P
)
5.0 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
6.8 Medium
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P
)
5.0 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
Vulnerability Type:
CWE-119
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2009-1722
Source: APPLE
Type: UNKNOWN
APPLE-SA-2009-08-05-1
Source: CCN
Type: Debian Web site
Debian -- Package Search Results -- openexr
Source: CCN
Type: SA36030
OpenEXR Multiple Vulnerabilities
Source: SECUNIA
Type: Vendor Advisory
36032
Source: CCN
Type: SA36096
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
Source: SECUNIA
Type: UNKNOWN
36096
Source: SECUNIA
Type: UNKNOWN
36753
Source: CONFIRM
Type: Patch
http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz
Source: CCN
Type: SECTRACK ID: 1022674
Mac OS X Multiple Image and File Processing Bugs Permit Remote Code Execution
Source: CCN
Type: Apple Web site
About Security Update 2009-003
Source: CONFIRM
Type: UNKNOWN
http://support.apple.com/kb/HT3757
Source: DEBIAN
Type: Patch
DSA-1842
Source: DEBIAN
Type: DSA-1842
openexr -- several vulnerabilities
Source: MANDRIVA
Type: UNKNOWN
MDVSA-2009:191
Source: CCN
Type: OpenEXR Web site
OpenEXR
Source: CCN
Type: OSVDB ID: 56709
OpenEXR Compression Implementation Unspecified Overflow
Source: BID
Type: Patch
35838
Source: CCN
Type: BID-35838
OpenEXR Multiple Memory Corruption Vulnerabilities
Source: SECTRACK
Type: UNKNOWN
1022674
Source: CCN
Type: USN-831-1
OpenEXR vulnerabilities
Source: UBUNTU
Type: UNKNOWN
USN-831-1
Source: CERT
Type: US Government Resource
TA09-218A
Source: VUPEN
Type: Vendor Advisory
ADV-2009-2035
Source: VUPEN
Type: UNKNOWN
ADV-2009-2172
Source: XF
Type: UNKNOWN
openexr-compressor-bo(52069)
Source: CONFIRM
Type: UNKNOWN
https://github.com/openexr/openexr/blob/master/CHANGES.md#version-170-july-23-2010
Vulnerable Configuration:
Configuration 1
:
cpe:/a:openexr:openexr:1.2.2:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:*
AND
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
OR
cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
OR
cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
OR
cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5.6:*:*:*:*:*:*:*
OR
cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:*
OR
cpe:/o:apple:mac_os_x_server:10.5.7:*:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.mitre.oval:def:13999
P
USN-831-1 -- openexr vulnerabilities
2014-06-30
oval:org.mitre.oval:def:7863
P
DSA-1842 openexr -- several vulnerabilities
2014-06-23
oval:org.debian:def:1842
V
several vulnerabilities
2009-07-28
BACK
openexr
openexr 1.2.2
apple
mac os x 10.5.6
mandrakesoft
mandrake linux corporate server 4.0
mandrakesoft
mandrake linux corporate server 4.0
mandrakesoft
mandrake linux 2008.0
debian
debian linux 4.0
mandrakesoft
mandrake linux 2008.0
apple
mac os x server 10.5
apple
mac os x 10.4.11
apple
mac os x 10.5.1
apple
mac os x server 10.4.11
apple
mac os x server 10.5.1
apple
mac os x 10.5.2
apple
mac os x server 10.5.2
canonical
ubuntu 8.04
apple
mac os x server 10.5.3
apple
mac os x 10.5.3
apple
mac os x 10.5.4
apple
mac os x server 10.5.4
apple
mac os x 10.5.5
apple
mac os x server 10.5.5
apple
mac os x server 10.5.6
debian
debian linux 5.0
apple
mac os x 10.5.0
apple
mac os x 10.5.7
apple
mac os x server 10.5.7