Openimageio: heap-buffer-overflow in file src/gif.imageio/gifinput.cpp
CVE-2023-3430

7.5HIGH

Key Information:

Vendor

Fedora

Vendor
CVE Published:
18 December 2023

What is CVE-2023-3430?

A vulnerability has been identified in OpenImageIO that allows for a heap buffer overflow due to improper processing in the gif.imageio/gifinput.cpp file. This flaw can be exploited by a remote attacker by sending a specially crafted file to the application, which can lead to a buffer overflow. The consequence of this vulnerability may include application crashes and potential denial of service, underscoring the importance of updating to secure versions.

Affected Version(s)

OpenImageIO 2.4.12.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.