### Description of Issue See https://github.com/AcademySoftwareFoundation/openexr/issues/1625 and https://takeonme.org/cves/CVE-2023-5841.html. A proposed fix is available in https://github.com/AcademySoftwareFoundation/openexr/pull/1627. ### Steps to Reproduce Observe that a slightly forked version of OpenEXR 3.2.0 is bundled in https://github.com/PixarAnimationStudios/OpenUSD/tree/v23.11/pxr/imaging/hio/OpenEXR, and compare with https://github.com/AcademySoftwareFoundation/openexr/issues/1625 and https://takeonme.org/cves/CVE-2023-5841.html. ### System Information (OS, Hardware) N/A ### Package Versions 23.11 ### Build Flags N/A
Description of Issue
See AcademySoftwareFoundation/openexr#1625 and https://takeonme.org/cves/CVE-2023-5841.html.
A proposed fix is available in AcademySoftwareFoundation/openexr#1627.
Steps to Reproduce
Observe that a slightly forked version of OpenEXR 3.2.0 is bundled in https://github.com/PixarAnimationStudios/OpenUSD/tree/v23.11/pxr/imaging/hio/OpenEXR, and compare with AcademySoftwareFoundation/openexr#1625 and https://takeonme.org/cves/CVE-2023-5841.html.
System Information (OS, Hardware)
N/A
Package Versions
23.11
Build Flags
N/A