Versions mentioned in the description apply to the upstream
Remediation section below for
Debian:9 relevant versions.
makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified other impact.
openexr to version 2.2.0-11+deb9u1 or higher.