Name | CVE-2024-40630 |
Description | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected versions there is a bug in the heif input functionality of OpenImageIO. Specifically, in `HeifInput::seek_subimage()`. In the worst case, this can lead to an information disclosure vulnerability, particularly for programs that directly use the `ImageInput` APIs. This bug has been addressed in commit `0a2dcb4c` which is included in the 2.5.13.1 release. Users are advised to upgrade. There are no known workarounds for this issue. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 1076772 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
openimageio (PTS) | jessie, jessie (lts) | 1.4.14~dfsg0-1+deb8u2 | vulnerable |
stretch (lts), stretch | 1.6.17~dfsg0-1+deb9u1 | vulnerable | |
buster (security), buster, buster (lts) | 2.0.5~dfsg0-1+deb10u2 | fixed | |
bullseye (security), bullseye | 2.2.10.1+dfsg-1+deb11u1 | vulnerable | |
bookworm | 2.4.7.1+dfsg-2 | vulnerable | |
sid | 2.5.16.0+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
openimageio | source | jessie | (unfixed) | end-of-life | ||
openimageio | source | stretch | (unfixed) | end-of-life | ||
openimageio | source | buster | (not affected) | |||
openimageio | source | (unstable) | 2.5.14.0+dfsg-1 | 1076772 |
[bookworm] - openimageio <no-dsa> (Minor issue)
[bullseye] - openimageio <no-dsa> (Minor issue)
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-jjm9-9m4m-c8p2
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/0a2dcb4cf2c3fd4825a146cd3ad929d9d8305ce3 (v2.5.13.1)
[buster] - openimageio <not-affected> (heif image support was added later)