CVE-2024-40630
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected versions there is a bug in the heif input functionality of OpenImageIO. Specifically, in `HeifInput::seek_subimage()`. In the worst case, this can lead to an information disclosure vulnerability, particularly for programs that directly use the `ImageInput` APIs. This bug has been addressed in commit `0a2dcb4c` which is included in the 2.5.13.1 release. Users are advised to upgrade. There are no known workarounds for this issue.
- Affected products
- Alt Linux, Debian, Openimageio
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.4% (37th percentile)
- Weakness
- CWE-125
- NVD status
- Deferred
- Published
- 2024-07-15
No indexed exploits for CVE-2024-40630 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-40630 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.