CVE-2023-36183

Name
CVE-2023-36183
Description
Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/OpenImageIO/oiio/issues/3871
MLIST https://lists.debian.org/debian-lts-announce/2023/08/msg00005.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OYFTS5LK725R6KVIYJVTPN3A6B6C7E6D/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CPHVMLS2LYMLURWFL7CMZ3Y7UMW3M4AW/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:* openimageio >= None <= 2.4.12.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
openimageio 3.18-community 2.4.11.0-r1 Leon Marz <main@lmarz.org> fixed