cbcvebase.
CVE-2024-40630
published 2024-07-15

CVE-2024-40630: OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with…

PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.45%
36.2th percentile
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected versions there is a bug in the heif input functionality of OpenImageIO. Specifically, in `HeifInput::seek_subimage()`. In the worst case, this can lead to an information disclosure vulnerability, particularly for programs that directly use the `ImageInput` APIs. This bug has been addressed in commit `0a2dcb4c` which is included in the 2.5.13.1 release. Users are advised to upgrade. There are no known workarounds for this issue.

Affected

4 ranges
VendorProductVersion rangeFixed in
academysoftwarefoundationopenimageio< 2.5.13.12.5.13.1
debianopenimageio< openimageio 2.5.14.0+dfsg-1 (forky)openimageio 2.5.14.0+dfsg-1 (forky)
openimageioopenimageio>= 0 < 2.5.14.0+dfsg-12.5.14.0+dfsg-1
openimageioopenimageio>= 0 < 2.5.14.0+dfsg-12.5.14.0+dfsg-1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.