Описание
A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
openimageio | fixed | 2.4.13.0+dfsg-1 | package | |
openimageio | no-dsa | bookworm | package | |
openimageio | no-dsa | bullseye | package | |
openimageio | no-dsa | buster | package |
Примечания
https://github.com/OpenImageIO/oiio/issues/3840
https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/3841
https://github.com/OpenImageIO/oiio/commit/5ff2c56dd28e96f67ed8f80d8a3d1235e51f9957 (v2.4.12.0)
EPSS
Связанные уязвимости
A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.
A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.
A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.
Уязвимость файла src/gif.imageio/gifinput.cpp библиотеки обработки изображений OpenImageIO, позволяющая нарушителю вызвать отказ в обслуживании
EPSS