CVE
- Id
- 39156
- CVE No.
- CVE-2009-1721
- Status
- Candidate
- Description
- The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
- Phase
- Assigned (20090520)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 430509 | 39156 | CVE-2009-1721 | CONFIRM:http://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiff | View |
| 430510 | 39156 | CVE-2009-1721 | CONFIRM:http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz | View |
| 430511 | 39156 | CVE-2009-1721 | CONFIRM:http://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gz | View |
| 430512 | 39156 | CVE-2009-1721 | CONFIRM:http://support.apple.com/kb/HT3757 | View |
| 430513 | 39156 | CVE-2009-1721 | APPLE:APPLE-SA-2009-08-05-1 | View |
| 430514 | 39156 | CVE-2009-1721 | URL:http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html | View |
| 430515 | 39156 | CVE-2009-1721 | DEBIAN:DSA-1842 | View |
| 430516 | 39156 | CVE-2009-1721 | URL:http://www.debian.org/security/2009/dsa-1842 | View |
| 430517 | 39156 | CVE-2009-1721 | FEDORA:FEDORA-2009-8132 | View |
| 430518 | 39156 | CVE-2009-1721 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.html | View |
| 430519 | 39156 | CVE-2009-1721 | FEDORA:FEDORA-2009-8136 | View |
| 430520 | 39156 | CVE-2009-1721 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.html | View |
| 430521 | 39156 | CVE-2009-1721 | MANDRIVA:MDVSA-2009:190 | View |
| 430522 | 39156 | CVE-2009-1721 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:190 | View |
| 430523 | 39156 | CVE-2009-1721 | MANDRIVA:MDVSA-2009:191 | View |
| 430524 | 39156 | CVE-2009-1721 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2009:191 | View |
| 430525 | 39156 | CVE-2009-1721 | UBUNTU:USN-831-1 | View |
| 430526 | 39156 | CVE-2009-1721 | URL:http://www.ubuntu.com/usn/USN-831-1 | View |
| 430527 | 39156 | CVE-2009-1721 | CERT:TA09-218A | View |
| 430528 | 39156 | CVE-2009-1721 | URL:http://www.us-cert.gov/cas/techalerts/TA09-218A.html | View |
| 430529 | 39156 | CVE-2009-1721 | BID:35838 | View |
| 430530 | 39156 | CVE-2009-1721 | URL:http://www.securityfocus.com/bid/35838 | View |
| 430531 | 39156 | CVE-2009-1721 | SECTRACK:1022674 | View |
| 430532 | 39156 | CVE-2009-1721 | URL:http://www.securitytracker.com/id?1022674 | View |
| 430533 | 39156 | CVE-2009-1721 | SECUNIA:36030 | View |
| 430534 | 39156 | CVE-2009-1721 | URL:http://secunia.com/advisories/36030 | View |
| 430535 | 39156 | CVE-2009-1721 | SECUNIA:36032 | View |
| 430536 | 39156 | CVE-2009-1721 | URL:http://secunia.com/advisories/36032 | View |
| 430537 | 39156 | CVE-2009-1721 | SECUNIA:36096 | View |
| 430538 | 39156 | CVE-2009-1721 | URL:http://secunia.com/advisories/36096 | View |
| 430539 | 39156 | CVE-2009-1721 | SECUNIA:36123 | View |
| 430540 | 39156 | CVE-2009-1721 | URL:http://secunia.com/advisories/36123 | View |
| 430541 | 39156 | CVE-2009-1721 | SECUNIA:36753 | View |
| 430542 | 39156 | CVE-2009-1721 | URL:http://secunia.com/advisories/36753 | View |
| 430543 | 39156 | CVE-2009-1721 | VUPEN:ADV-2009-2035 | View |
| 430544 | 39156 | CVE-2009-1721 | URL:http://www.vupen.com/english/advisories/2009/2035 | View |
| 430545 | 39156 | CVE-2009-1721 | VUPEN:ADV-2009-2172 | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 40883 | JVNDB-2009-001889 | Apple Safari の WebKit における任意のコードを実行される脆弱性 | Apple Safari の WebKit には、数値参照を適切に処理しないため、任意のコードを実行される、あるいはサービス運用妨害 (DoS) 状態となる脆弱性が存在します。 | CVE-2009-1725 | 39156 | 9.3 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001889.html | View |