Impact
OpenImageIO can perform unbounded recursion when parsing FITS headers that contain consecutive 2880‑byte blocks without the required END keyword. The recursive call to fitsinput::read_fits_header() has no depth bound, causing the application stack to be exhausted and the process to terminate. This flaw is formally categorized as CWE‑674 and results in a denial of service rather than information disclosure or privilege escalation.
Affected Systems
The vulnerability affects the Academy Software Foundation’s OpenImageIO toolset, which is used to read, write, and manipulate image files in VFX and animation pipelines. Versions before the releases 3.0.20.0, 3.1.15.0, and 3.2.0.3‑beta1 are impacted. These releases contain the parser bug in src/fits.imageio/fitsinput.cpp, specifically within the FitsInput::read_fits_header() function that processes FITS header blocks.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not a known exploited vulnerability. The likely attack vector involves supplying a crafted FITS file to a vulnerable consumer of OpenImageIO, such as a VFX rendering pipeline or image conversion tool. Successful exploitation would result in a process crash or loss of service for the affected application, with the impact limited to denial of service but with significant operational impact in production environments.
OpenCVE Enrichment