OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Version 3.3.2 is vulnerable to a heap-based buffer overflow during a read operation due to bad pointer math when decompressing DWAA-packed scan-line EXR files with a maliciously forged chunk. This is fixed in version 3.3.3.
History

Wed, 13 Aug 2025 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:openexr:openexr:3.3.2:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Mon, 04 Aug 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Openexr
Openexr openexr
Vendors & Products Openexr
Openexr openexr

Fri, 01 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

threat_severity

Moderate


Thu, 31 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 20:30:00 +0000

Type Values Removed Values Added
Description OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Version 3.3.2 is vulnerable to a heap-based buffer overflow during a read operation due to bad pointer math when decompressing DWAA-packed scan-line EXR files with a maliciously forged chunk. This is fixed in version 3.3.3.
Title OpenEXR's Inaccurate Pointer Arithmetic can Cause an Out of Bounds Heap
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-31T20:18:40.598Z

Updated: 2025-07-31T20:37:21.287Z

Reserved: 2025-05-15T16:06:40.942Z

Link: CVE-2025-48072

cve-icon Vulnrichment

Updated: 2025-07-31T20:37:16.047Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-31T21:15:28.163

Modified: 2025-08-13T20:23:43.777

Link: CVE-2025-48072

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-31T20:18:40Z

Links: CVE-2025-48072 - Bugzilla