CVE
- Id
- 39155
- CVE No.
- CVE-2009-1720
- Status
- Candidate
- Description
- Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.
- Phase
- Assigned (20090520)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
430472 | 39155 | CVE-2009-1720 | CONFIRM:http://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiff | View |
430473 | 39155 | CVE-2009-1720 | CONFIRM:http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz | View |
430474 | 39155 | CVE-2009-1720 | CONFIRM:http://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gz | View |
430475 | 39155 | CVE-2009-1720 | CONFIRM:http://support.apple.com/kb/HT3757 | View |
430476 | 39155 | CVE-2009-1720 | APPLE:APPLE-SA-2009-08-05-1 | View |
430477 | 39155 | CVE-2009-1720 | URL:http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html | View |
430478 | 39155 | CVE-2009-1720 | DEBIAN:DSA-1842 | View |
430479 | 39155 | CVE-2009-1720 | URL:http://www.debian.org/security/2009/dsa-1842 | View |
430480 | 39155 | CVE-2009-1720 | FEDORA:FEDORA-2009-8132 | View |
430481 | 39155 | CVE-2009-1720 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.html | View |
430482 | 39155 | CVE-2009-1720 | FEDORA:FEDORA-2009-8136 | View |
430483 | 39155 | CVE-2009-1720 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.html | View |
430484 | 39155 | CVE-2009-1720 | MANDRIVA:MDVSA-2009:190 | View |
430485 | 39155 | CVE-2009-1720 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:190 | View |
430486 | 39155 | CVE-2009-1720 | MANDRIVA:MDVSA-2009:191 | View |
430487 | 39155 | CVE-2009-1720 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:191 | View |
430488 | 39155 | CVE-2009-1720 | UBUNTU:USN-831-1 | View |
430489 | 39155 | CVE-2009-1720 | URL:http://www.ubuntu.com/usn/USN-831-1 | View |
430490 | 39155 | CVE-2009-1720 | CERT:TA09-218A | View |
430491 | 39155 | CVE-2009-1720 | URL:http://www.us-cert.gov/cas/techalerts/TA09-218A.html | View |
430492 | 39155 | CVE-2009-1720 | BID:35838 | View |
430493 | 39155 | CVE-2009-1720 | URL:http://www.securityfocus.com/bid/35838 | View |
430494 | 39155 | CVE-2009-1720 | SECTRACK:1022674 | View |
430495 | 39155 | CVE-2009-1720 | URL:http://www.securitytracker.com/id?1022674 | View |
430496 | 39155 | CVE-2009-1720 | SECUNIA:36030 | View |
430497 | 39155 | CVE-2009-1720 | URL:http://secunia.com/advisories/36030 | View |
430498 | 39155 | CVE-2009-1720 | SECUNIA:36032 | View |
430499 | 39155 | CVE-2009-1720 | URL:http://secunia.com/advisories/36032 | View |
430500 | 39155 | CVE-2009-1720 | SECUNIA:36096 | View |
430501 | 39155 | CVE-2009-1720 | URL:http://secunia.com/advisories/36096 | View |
430502 | 39155 | CVE-2009-1720 | SECUNIA:36123 | View |
430503 | 39155 | CVE-2009-1720 | URL:http://secunia.com/advisories/36123 | View |
430504 | 39155 | CVE-2009-1720 | SECUNIA:36753 | View |
430505 | 39155 | CVE-2009-1720 | URL:http://secunia.com/advisories/36753 | View |
430506 | 39155 | CVE-2009-1720 | VUPEN:ADV-2009-2035 | View |
430507 | 39155 | CVE-2009-1720 | URL:http://www.vupen.com/english/advisories/2009/2035 | View |
430508 | 39155 | CVE-2009-1720 | VUPEN:ADV-2009-2172 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
40882 | JVNDB-2009-001888 | Apple Safari の WebKit におけるクロスサイトスクリプティングの脆弱性 | Apple Safari の WebKit には、parent および top オブジェクトの処理に関して不備があるため、クロスサイトスクリプティングの脆弱性が存在します。 | CVE-2009-1724 | 39155 | 4.3 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001888.html | View |