Description
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
References (2)
Core 2
Core References
Third Party Advisory
https://security.gentoo.org/glsa/202305-33
Exploit, Third Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1630
Scores
CVSS v3
9.8
EPSS
0.0142
EPSS Percentile
69.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-123
CWE-787
Status
published
Products (1)
openimageio/openimageio
2.3.19.0
Published
Dec 22, 2022
Tracked Since
Feb 18, 2026