CVE-2023-24473: High severity openimageio vulnerability
Published Mar 30, 2023
·Updated
An information disclosure vulnerability exists in the TGAInput::readtga2header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Openimageio Openimageio=2.4.7.1
Event History
Mar 30, 2023
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this information disclosure vulnerability?
The vulnerability ID for this information disclosure vulnerability is CVE-2023-24473.
2
What is the affected software?
The affected software is OpenImageIO Project OpenImageIO version 2.4.7.1.
3
What is the severity of CVE-2023-24473?
The severity of CVE-2023-24473 is high with a CVSS score of 7.5.
4
What is the description of the vulnerability?
The vulnerability allows a specially crafted targa file to disclose sensitive information.
5
How can the vulnerability be exploited?
An attacker can provide a malicious file to trigger the information disclosure vulnerability.