PT-2024-28952 · Unknown+2 · Openimageio+2

Flyyee

·

Published

2024-07-15

·

Updated

2024-07-31

·

CVE-2024-40630

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenImageIO versions prior to 2.5.13.1
Description The issue is related to a bug in the heif input functionality of OpenImageIO, specifically in the HeifInput::seek subimage() function. This bug can lead to an information disclosure issue, particularly for programs that directly use the ImageInput APIs.
Recommendations For versions prior to 2.5.13.1, upgrade to version 2.5.13.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the HeifInput::seek subimage() function until the upgrade is applied.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10195
CVE-2024-40630
GHSA-JJM9-9M4M-C8P2
OPENSUSE-SU-2024:14200-1

Affected Products

Alt Linux
Debian
Openimageio