CVE-2017-12596: Openexr
High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.
In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.
Affected products
- Openexr Openexr: version 2.2.0 only
Published 2017-08-07. Last modified 2026-06-17.