Impact
OpenSlide’s parse_level0_xml() routine, when processing Ventana BIF files, accepts nonpositive row or column tile counts beginning with version 3.4.1. These invalid counts generate attacker‑controlled relative memory offsets that allow arbitrary data to be written at those offsets. The write can corrupt the process’s memory, potentially leading to a crash or remote code execution on any platform or configuration that uses the vulnerable OpenSlide library.
Affected Systems
The vulnerability affects the OpenSlide project and its library, OpenSlide. All supported platforms that use the library from version 3.4.1 up through 4.0.1 are impacted. The issue is fixed in OpenSlide version 4.0.1 and later.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity and the EPSS score of less than 1% suggests a low probability of exploitation at present, but it is still listed as not yet in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is an attacker supplying a malicious BIF file to any application that loads slide images using the affected OpenSlide library, which could lead to arbitrary code execution. The vulnerability exists due to improper bounds checking of tile count values (CWE-123, CWE-1284, CWE-823).
OpenCVE Enrichment