CVE-2024-55192: Critical severity openimageio vulnerability
Published Jan 23, 2025
·Updated
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIOv310::farmhash::inlined::Fetch64(char const).
Affected Software
2 affected components
Openimageio Openimageio
Openimageio Openimageio=3.1.0.0-dev
Event History
Jan 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55192?
CVE-2024-55192 has been classified as a moderate severity vulnerability due to its potential for heap overflow.
2
How do I fix CVE-2024-55192?
To mitigate CVE-2024-55192, you should update OpenImageIO to the latest stable version that addresses this vulnerability.
3
What component is affected by CVE-2024-55192?
CVE-2024-55192 affects the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64.
4
Which version of OpenImageIO is vulnerable to CVE-2024-55192?
OpenImageIO v3.1.0.0dev is the specific version identified as vulnerable to CVE-2024-55192.
5
What are the potential impacts of CVE-2024-55192?
CVE-2024-55192 could lead to application crashes or arbitrary code execution due to the heap overflow.