PT-2026-41025 · Unknown+2 · Openimageio+2
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenImageIO versions prior to 3.0.18.0
OpenImageIO versions prior to 3.1.13.0
Description
OpenImageIO is a toolset for reading, writing, and manipulating image files for VFX and animation. A heap-based buffer overflow occurs in the HEIF decoder when processing crafted images with a subimage metadata mismatch. This leads to out-of-bounds writes, resulting in memory corruption and potential code execution.
Recommendations
Update to version 3.0.18.0.
Update to version 3.1.13.0.
Exploit
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Openimageio
Ubuntu