CVE-2023-42299: Buffer Overflow
Published Nov 2, 2023
·Updated
Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the readsubimagedata function.
Affected Software
1 affected component
Openimageio Openimageio=2.4.12.0
Remediation
Patch Available
Event History
Nov 2, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this buffer overflow vulnerability?
The vulnerability ID for this buffer overflow vulnerability is CVE-2023-42299.
2
What is the affected software?
The affected software is OpenImageIO oiio version 2.4.12.0.
3
What is the severity of CVE-2023-42299?
The severity of CVE-2023-42299 is critical with a severity value of 9.8.
4
How does CVE-2023-42299 impact the system?
CVE-2023-42299 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.
5
Is there a fix available?
For details on the fix for CVE-2023-42299, please refer to the official OpenImageIO GitHub repository at https://github.com/OpenImageIO/oiio/issues/3840.