Bugzilla – Bug 1216852
VUL-0: CVE-2023-42299: OpenImageIO: Buffer Overflow in OpenImageIO oiio
Last modified: 2023-11-03 09:15:02 UTC
Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-42299
Was fixed in v.2.4.13.0, so Factory is not affected. Tracking as affected: - openSUSE:Backports:SLE-15-SP4/OpenImageIO 2.2.17.0 - openSUSE:Backports:SLE-15-SP5/OpenImageIO 2.2.17.0 as they contain the affected code. Upstream fix: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/3841