<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">libIex-3_3-32-3.3.5-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2025:15415-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-08-06T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-08-06T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-08-06T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">libIex-3_3-32-3.3.5-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the libIex-3_3-32-3.3.5-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2025-15415</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-48071/</URL>
      <Description>SUSE CVE CVE-2025-48071 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-48072/</URL>
      <Description>SUSE CVE CVE-2025-48072 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-48073/</URL>
      <Description>SUSE CVE CVE-2025-48073 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-48074/</URL>
      <Description>SUSE CVE CVE-2025-48074 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libIex-3_3-32-3.3.5-1.1">
      <FullProductName ProductID="libIex-3_3-32-3.3.5-1.1">libIex-3_3-32-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libIex-3_3-32-32bit-3.3.5-1.1">
      <FullProductName ProductID="libIex-3_3-32-32bit-3.3.5-1.1">libIex-3_3-32-32bit-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libIex-3_3-32-x86-64-v3-3.3.5-1.1">
      <FullProductName ProductID="libIex-3_3-32-x86-64-v3-3.3.5-1.1">libIex-3_3-32-x86-64-v3-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libIlmThread-3_3-32-3.3.5-1.1">
      <FullProductName ProductID="libIlmThread-3_3-32-3.3.5-1.1">libIlmThread-3_3-32-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libIlmThread-3_3-32-32bit-3.3.5-1.1">
      <FullProductName ProductID="libIlmThread-3_3-32-32bit-3.3.5-1.1">libIlmThread-3_3-32-32bit-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1">
      <FullProductName ProductID="libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1">libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXR-3_3-32-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXR-3_3-32-3.3.5-1.1">libOpenEXR-3_3-32-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXR-3_3-32-32bit-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXR-3_3-32-32bit-3.3.5-1.1">libOpenEXR-3_3-32-32bit-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1">libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXRCore-3_3-32-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXRCore-3_3-32-3.3.5-1.1">libOpenEXRCore-3_3-32-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXRCore-3_3-32-32bit-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXRCore-3_3-32-32bit-3.3.5-1.1">libOpenEXRCore-3_3-32-32bit-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1">libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXRUtil-3_3-32-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXRUtil-3_3-32-3.3.5-1.1">libOpenEXRUtil-3_3-32-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1">libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1">
      <FullProductName ProductID="libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1">libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openexr-3.3.5-1.1">
      <FullProductName ProductID="openexr-3.3.5-1.1">openexr-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openexr-devel-3.3.5-1.1">
      <FullProductName ProductID="openexr-devel-3.3.5-1.1">openexr-devel-3.3.5-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openexr-doc-3.3.5-1.1">
      <FullProductName ProductID="openexr-doc-3.3.5-1.1">openexr-doc-3.3.5-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libIex-3_3-32-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libIex-3_3-32-3.3.5-1.1">libIex-3_3-32-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libIex-3_3-32-32bit-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libIex-3_3-32-32bit-3.3.5-1.1">libIex-3_3-32-32bit-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libIex-3_3-32-x86-64-v3-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libIex-3_3-32-x86-64-v3-3.3.5-1.1">libIex-3_3-32-x86-64-v3-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libIlmThread-3_3-32-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libIlmThread-3_3-32-3.3.5-1.1">libIlmThread-3_3-32-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libIlmThread-3_3-32-32bit-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libIlmThread-3_3-32-32bit-3.3.5-1.1">libIlmThread-3_3-32-32bit-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1">libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXR-3_3-32-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXR-3_3-32-3.3.5-1.1">libOpenEXR-3_3-32-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXR-3_3-32-32bit-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXR-3_3-32-32bit-3.3.5-1.1">libOpenEXR-3_3-32-32bit-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1">libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXRCore-3_3-32-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXRCore-3_3-32-3.3.5-1.1">libOpenEXRCore-3_3-32-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXRCore-3_3-32-32bit-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXRCore-3_3-32-32bit-3.3.5-1.1">libOpenEXRCore-3_3-32-32bit-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1">libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXRUtil-3_3-32-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-3.3.5-1.1">libOpenEXRUtil-3_3-32-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1">libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1">libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openexr-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openexr-3.3.5-1.1">openexr-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openexr-devel-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openexr-devel-3.3.5-1.1">openexr-devel-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="openexr-doc-3.3.5-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:openexr-doc-3.3.5-1.1">openexr-doc-3.3.5-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.2 through 3.3.0, there is a heap-based buffer overflow during a write operation when decompressing ZIPS-packed deep scan-line EXR files with a maliciously forged chunk header. This is fixed in version 3.3.3.</Note>
    </Notes>
    <CVE>CVE-2025-48071</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-devel-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-doc-3.3.5-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-48071.html</URL>
        <Description>CVE-2025-48071</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1247552</URL>
        <Description>SUSE Bug 1247552</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Version 3.3.2 is vulnerable to a heap-based buffer overflow during a read operation due to bad pointer math when decompressing DWAA-packed scan-line EXR files with a maliciously forged chunk. This is fixed in version 3.3.3.</Note>
    </Notes>
    <CVE>CVE-2025-48072</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-devel-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-doc-3.3.5-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-48072.html</URL>
        <Description>CVE-2025-48072</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1247551</URL>
        <Description>SUSE Bug 1247551</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.</Note>
    </Notes>
    <CVE>CVE-2025-48073</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-devel-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-doc-3.3.5-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-48073.html</URL>
        <Description>CVE-2025-48073</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1247550</URL>
        <Description>SUSE Bug 1247550</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.</Note>
    </Notes>
    <CVE>CVE-2025-48074</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIex-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libIlmThread-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXR-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRCore-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-32bit-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libOpenEXRUtil-3_3-32-x86-64-v3-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-devel-3.3.5-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:openexr-doc-3.3.5-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-48074.html</URL>
        <Description>CVE-2025-48074</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1247504</URL>
        <Description>SUSE Bug 1247504</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
