Bug 2341859 (CVE-2024-55194)

Summary: CVE-2024-55194 OpenImageIO: OpenImageIO: Remote code execution due to heap overflow vulnerability in fmath.h
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in OpenImageIO. This heap overflow vulnerability, located in the `fmath.h` component, could allow a remote attacker to execute arbitrary code. By processing specially crafted input, an attacker could trigger the overflow, leading to potential system compromise, including privilege escalation and denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2341893, 2341895, 2341898, 2341900    
Bug Blocks:    

Description OSIDB Bzimport 2025-01-23 23:01:27 UTC
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.