CVE-2025-48071

Severity CVSS v4.0:
HIGH
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
31/07/2025
Last modified:
13/08/2025

Description

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operation when decompressing ZIPS-packed deep scan-line EXR files with a maliciously forged chunk header. This is fixed in version 3.3.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* 3.3.0 (including) 3.3.3 (excluding)