CRITICAL🇵🇱 Wersja polska

CVE-2024-55192

CVSS 9.8v3.1pub. 2025-01-23upd. 2025-02-05

OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).

🤖 AI Analysis
How it works

The vulnerability consists of a heap buffer overflow (CWE-122/CWE-787) in the function OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*). An attacker can provide specially crafted input data that causes writes beyond the boundaries of the allocated heap buffer. Due to the network vector (AV:N) and lack of privilege and user interaction requirements (PR:N, UI:N), the exploit can be performed remotely and fully automatically.

Impact

Successful exploitation of the vulnerability can lead to arbitrary code execution (RCE) in the context of the process using the library, as well as breach of confidentiality, integrity and system availability.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references. It is recommended to monitor the official project repository (AcademySoftwareFoundation/OpenImageIO) to obtain an updated version containing the fix.

Who is affected

OpenImageIO v3.1.0.0dev

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openimageio

    APP
    Openimageio
    3.1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-55194CRITICAL9.8PL ✓same product

Heap overflow w OpenImageIO przez komponent fmath.h

CVE-2024-55193CRITICAL9.8PL ✓same product

Naruszenie segmentacji (segfault) w OpenImageIO przez komponent string_view.h

CVE-2023-42299CRITICAL9.8PL ✓same product

Buffer Overflow w OpenImageIO umożliwiający RCE i DoS

CVE-2022-41639CRITICAL9.8PL ✓same product

Heap buffer overflow w parserze TIFF biblioteki OpenImageIO — możliwe RCE

CVE-2022-38143CRITICAL9.8PL ✓same product

OpenImageIO: heap out-of-bounds write przy przetwarzaniu obrazów BMP z kodowaniem RLE