CRITICAL🇵🇱 Wersja polska

CVE-2024-55193

CVSS 9.8v3.1pub. 2025-01-23upd. 2025-01-29

OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.

🤖 AI Analysis
How it works

The vulnerability results from improper pointer handling (CWE-476 — NULL pointer dereference) in the string_view.h component of the OpenImageIO library. Processing appropriately crafted input data leads to a segmentation fault in the process, resulting in unpredictable application behavior. The error is accessible remotely, without requiring authentication or user interaction (attack vector AV:N/AC:L/PR:N/UI:N).

Impact

An attacker can cause application crashes (denial of service) or — depending on the runtime environment — potentially remote code execution (RCE) with violation of data confidentiality, integrity, and availability.

Mitigation & patch

Patches available from the vendor should be applied according to references. It is recommended to monitor updates in the project repository (https://github.com/AcademySoftwareFoundation/OpenImageIO) and avoid processing untrusted image files until the fix is implemented.

Who is affected

OpenImageIO v3.1.0.0dev (development version); the detailed version scope should be verified in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openimageio

    APP
    Openimageio
    3.1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-55194CRITICAL9.8PL ✓same product

Heap overflow w OpenImageIO przez komponent fmath.h

CVE-2024-55192CRITICAL9.8PL ✓same product

Heap overflow w OpenImageIO poprzez komponent Fetch64

CVE-2023-42299CRITICAL9.8PL ✓same product

Buffer Overflow w OpenImageIO umożliwiający RCE i DoS

CVE-2022-41639CRITICAL9.8PL ✓same product

Heap buffer overflow w parserze TIFF biblioteki OpenImageIO — możliwe RCE

CVE-2022-38143CRITICAL9.8PL ✓same product

OpenImageIO: heap out-of-bounds write przy przetwarzaniu obrazów BMP z kodowaniem RLE