Memory Allocation Vulnerability in OpenEXR 3.3.2 by Academy Software Foundation
CVE-2025-48074
4.6MEDIUM
What is CVE-2025-48074?
A vulnerability exists in OpenEXR version 3.3.2 that allows applications to trust unvalidated dataWindow size values from file headers. This oversight can result in excessive memory allocation, which may lead to performance degradation when processing potentially malicious EXR files. Users are encouraged to upgrade to version 3.3.3, where this issue has been addressed.
Affected Version(s)
openexr >= 3.3.2, < 3.3.3