CVE-2023-42295Integer Overflow or Wraparound in Openimageio

Severity
8.8HIGHNVD
EPSS
1.5%
top 19.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23

Description

An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

debiandebian/openimageio< openimageio 2.4.16.0+dfsg-1 (forky)
Debianopenimageio/openimageio< 2.4.16.0+dfsg-1+1

🔴Vulnerability Details

2
OSV
CVE-2023-42295: An issue in OpenImageIO oiio v2023-10-23
GHSA
GHSA-834h-7mjv-2g94: An issue in OpenImageIO oiio v2023-10-23

📋Vendor Advisories

1
Debian
CVE-2023-42295: openimageio - An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbi...2023