A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2218380 | Issue Tracking Third Party Advisory | 
| https://github.com/AcademySoftwareFoundation/OpenImageIO/issues/3840 | Exploit Third Party Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=2218380 | Issue Tracking Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 08:17
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2218380 - Issue Tracking, Third Party Advisory | 
22 Dec 2023, 18:44
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:openimageio:openimageio:2.4.11:*:*:*:*:*:*:* cpe:2.3:o:redhat:linux:-:*:*:*:*:*:*:* | |
| CWE | CWE-787 | |
| First Time | Redhat Openimageio Redhat linux Openimageio openimageio | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.5 | 
| References | 
 | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2218380 - Issue Tracking, Third Party Advisory | 
18 Dec 2023, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-12-18 14:15
Updated : 2024-11-21 08:17
NVD link : CVE-2023-3430
Mitre link : CVE-2023-3430
CVE.ORG link : CVE-2023-3430
JSON object : View
Products Affected
                redhat
- linux
openimageio
- openimageio
