CVE-2023-3430: Openimageio: heap-buffer-overflow in file src/gif.imageio/gifinput.cpp
A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.
Other sources
A vulnerability was found in OpenImageIO, where heap-buffer-overflow exists in file src/gif.imageio/gifinput.cpp.
References: https://github.com/OpenImageIO/oiio/issues/3840
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3430?
The severity of CVE-2023-3430 is considered high due to the potential for remote exploitation through a heap buffer overflow.
How do I fix CVE-2023-3430?
To fix CVE-2023-3430, upgrade OpenImageIO to version 2.4.12.0 or later.
Which versions of OpenImageIO are affected by CVE-2023-3430?
OpenImageIO versions prior to 2.4.12.0, specifically 2.4.11, are affected by CVE-2023-3430.
Can CVE-2023-3430 cause denial of service?
Yes, CVE-2023-3430 can cause a denial of service by triggering a crash in the application due to the buffer overflow.
What components of OpenImageIO are impacted by CVE-2023-3430?
CVE-2023-3430 specifically impacts the gifimageio component within OpenImageIO, located in gifinput.cpp.