{"id":"GHSA-99jg-r3f4-rpxj","summary":"memory overflow vulnerability in OpenEXR-viewer","details":"Just open this exr file through openexr-viewer.\n\n( poc send by email )\n\nThis is windbg log file.\n\n[ POC 2 ]\n(8660.7e44): Access violation - code c0000005 (!!! second chance !!!)\nopenexr_viewer+0x27be4:\n00007ff7`13ff7be4 c744880c0000803f mov     dword ptr [rax+rcx*4+0Ch],3F800000h ds:0000020a`3ac8000c=????????\n\nAttempt to write the value 1.0 to the memory address 0x20A3AC8000C\n\n[ POC 1 ]\n(1404.9264): Access violation - code c0000005 (first chance)\nFirst chance exceptions are reported before any exception handling.\nThis exception may be expected and handled.\nopenexr_viewer+0x27be4:\n00007ff7`13ff7be4 c744880c0000803f mov     dword ptr [rax+rcx*4+0Ch],3F800000h ds:0000029c`b371600c=????????\n\nAttempt to write the value 1.0 to the memory address 0x29CB371600C\n\n\nCredits\nTeam : ZeroPointer\n이동하 ( Lee Dong Ha of ZeroPointer Lab )\n정지민    ( Jeong Jimin of ZeroPointer Lab )\n박우진    ( Park Woojin of ZeroPointer Lab )\n전우진    ( Jeon Woojin of ZeroPointer Lab )\n","aliases":["CVE-2023-50245"],"modified":"2023-12-12T13:41:33.264924Z","published":"2023-12-12T13:20:29Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-12-12T13:20:29Z","nvd_published_at":"2023-12-11T23:15:08Z","cwe_ids":["CWE-120"]},"references":[{"type":"WEB","url":"https://github.com/afichet/openexr-viewer/security/advisories/GHSA-99jg-r3f4-rpxj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50245"},{"type":"WEB","url":"https://github.com/afichet/openexr-viewer/commit/d0a7e85dfeb519951fb8a8d70f73f30d41cdd3d9"},{"type":"PACKAGE","url":"https://github.com/afichet/openexr-viewer"}],"affected":[{"package":{"name":"afichet/openexr-viewer","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-99jg-r3f4-rpxj/GHSA-99jg-r3f4-rpxj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}