OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
The vulnerability results from improper pointer handling (CWE-476 — NULL pointer dereference) in the string_view.h component of the OpenImageIO library. Processing appropriately crafted input data leads to a segmentation fault in the process, resulting in unpredictable application behavior. The error is accessible remotely, without requiring authentication or user interaction (attack vector AV:N/AC:L/PR:N/UI:N).
An attacker can cause application crashes (denial of service) or — depending on the runtime environment — potentially remote code execution (RCE) with violation of data confidentiality, integrity, and availability.
Patches available from the vendor should be applied according to references. It is recommended to monitor updates in the project repository (https://github.com/AcademySoftwareFoundation/OpenImageIO) and avoid processing untrusted image files until the fix is implemented.
OpenImageIO v3.1.0.0dev (development version); the detailed version scope should be verified in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenimageio
APPOpenimageio3.1.0.0
Related vulnerabilities
Heap overflow w OpenImageIO przez komponent fmath.h
Heap overflow w OpenImageIO poprzez komponent Fetch64
Buffer Overflow w OpenImageIO umożliwiający RCE i DoS
Heap buffer overflow w parserze TIFF biblioteki OpenImageIO — możliwe RCE
OpenImageIO: heap out-of-bounds write przy przetwarzaniu obrazów BMP z kodowaniem RLE