CVE-2024-40630
HEIF Heap OOB Read in OpenImageIO
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected versions there is a bug in the heif input functionality of OpenImageIO. Specifically, in `HeifInput::seek_subimage()`. In the worst case, this can lead to an information disclosure vulnerability, particularly for programs that directly use the `ImageInput` APIs. This bug has been addressed in commit `0a2dcb4c` which is included in the 2.5.13.1 release. Users are advised to upgrade. There are no known workarounds for this issue.
OpenImageIO es un conjunto de herramientas para leer, escribir y manipular archivos de imágenes de cualquier formato de archivo de imagen relevante para VFX/animación a través de una API independiente del formato con un conjunto de funciones, escalabilidad y solidez necesarias para la producción de largometrajes. En las versiones afectadas hay un error en la funcionalidad de entrada heif de OpenImageIO. Específicamente, en `HeifInput::seek_subimage()`. En el peor de los casos, esto puede provocar una vulnerabilidad de divulgación de información, especialmente para programas que utilizan directamente las API "ImageInput". Este error se solucionó en el commit `0a2dcb4c` que se incluye en la versión 2.5.13.1. Se recomienda a los usuarios que actualicen. No se conocen workarounds para este problema.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-07-08 CVE Reserved
- 2024-07-15 CVE Published
- 2024-07-16 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
AcademySoftwareFoundation Search vendor "AcademySoftwareFoundation" | OpenImageIO Search vendor "AcademySoftwareFoundation" for product "OpenImageIO" | < 2.5.13.1 Search vendor "AcademySoftwareFoundation" for product "OpenImageIO" and version " < 2.5.13.1" | en |
Affected
|