Out-of-bounds read In openimageio
Description
An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2.2.10.1+dfsg-1+deb11u1 | ||
debian 12 | 2.4.7.1+dfsg-2 | ||
debian 13 | 2.4.7.1+dfsg-2 | ||
debian 14 | 2.4.7.1+dfsg-2 |
Aliases
1. 2. 3. 4. 5.