cbcvebase.

Debian Openimageio vulnerabilities

34 known vulnerabilities affecting debian/openimageio.

Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH15MEDIUM10LOW1

Vulnerabilities

Page 2 of 2
CVE-2022-41999P3HIGHCVSS 7.5fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-41999 [HIGH] CVE-2022-41999: openimageio - A denial of service vulnerability exists in the DDS native tile reading function... A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.4.7.1+dfsg-2) bullseye: resolved (fixed in 2.2.
debian
CVE-2023-24472P3HIGHCVSS 7.5fixed in openimageio 2.4.13.0+dfsg-1 (forky)2023
CVE-2023-24472 [HIGH] CVE-2023-24472: openimageio - A denial of service vulnerability exists in the FitsOutput::close() functionalit... A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide malicious input to trigger this vulnerability. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.4.13.0+dfsg-1) sid: resol
debian
CVE-2024-55195P3HIGHCVSS 7.5fixed in openimageio 2.5.18.0+dfsg-1 (forky)2024
CVE-2024-55195 [HIGH] CVE-2024-55195: openimageio - An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.... An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (DoS) when the program to requests to allocate too much space. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.5.18.0+dfsg-1) sid: resolved (fixed in 2.5.18.0+dfsg-1) trixie: resolved (fixed in 2.5.18.0+dfsg-1)
debian
CVE-2023-36183P4HIGHCVSS 7.8fixed in openimageio 2.4.13.0+dfsg-1 (forky)2023
CVE-2023-36183 [HIGH] CVE-2023-36183: openimageio - Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remo... Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.4.13.0+dfsg-1) sid: resolved (fixed in 2.4.13.0+dfsg-1) trixie: resolved (fixed in 2.4.13.0+dfsg-1)
debian
CVE-2022-43596P4MEDIUMCVSS 5.9fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-43596 [MEDIUM] CVE-2022-43596: openimageio - An information disclosure vulnerability exists in the IFFOutput channel interlea... An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.4.7.1+dfsg-2) bullseye: resolved (
debian
CVE-2022-43592P4MEDIUMCVSS 5.9fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-43592 [MEDIUM] CVE-2022-43592: openimageio - An information disclosure vulnerability exists in the DPXOutput::close() functio... An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.4.7.1+dfsg-2) bullseye: resolved (fixed in 2.2
debian
CVE-2022-43594P4MEDIUMCVSS 5.9fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-43594 [MEDIUM] CVE-2022-43594: openimageio - Multiple denial of service vulnerabilities exist in the image output closing fun... Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files. Scope:
debian
CVE-2022-43595P4MEDIUMCVSS 5.9fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-43595 [MEDIUM] CVE-2022-43595: openimageio - Multiple denial of service vulnerabilities exist in the image output closing fun... Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .fits files. Scope:
debian
CVE-2022-43593P4MEDIUMCVSS 5.9fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-43593 [MEDIUM] CVE-2022-43593: openimageio - A denial of service vulnerability exists in the DPXOutput::close() functionality... A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.4.7.1+dfsg-2) bullseye: resolved (fixed in 2
debian
CVE-2022-43603P4MEDIUMCVSS 5.9fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-43603 [MEDIUM] CVE-2022-43603: openimageio - A denial of service vulnerability exists in the ZfileOutput::close() functionali... A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.4.7.1+dfsg-2) bullseye: resolved (fixed in 2.2.1
debian
CVE-2022-36354P4MEDIUMCVSS 5.3fixed in openimageio 2.3.21.0+dfsg-1 (bookworm)2022
CVE-2022-36354 [MEDIUM] CVE-2022-36354: openimageio - A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenI... A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. An attacker can provide a malicious file to
debian
CVE-2022-41684P4MEDIUMCVSS 5.5fixed in openimageio 2.4.7.1+dfsg-2 (bookworm)2022
CVE-2022-41684 [MEDIUM] CVE-2022-41684: openimageio - A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-... A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: re
debian
CVE-2024-40630P4MEDIUMCVSS 4.3fixed in openimageio 2.5.14.0+dfsg-1 (forky)2024
CVE-2024-40630 [MEDIUM] CVE-2024-40630: openimageio - OpenImageIO is a toolset for reading, writing, and manipulating image files of a... OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected versions there is a bug in the heif input functionality of OpenImageIO. Specifically, in `HeifInput::seek_subim
debian
CVE-2022-41977P4LOWCVSS 3.3fixed in openimageio 2.3.21.0+dfsg-1 (bookworm)2022
CVE-2022-41977 [LOW] CVE-2022-41977: openimageio - An out of bounds read vulnerability exists in the way OpenImageIO version v2.3.1... An out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF image files. A specially-crafted TIFF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.3.21.0+dfsg-1) bullseye: resolved (fixed in 2.2.10.1+d
debian
Debian Openimageio vulnerabilities | cvebase