Impact
A crafted Cineon file can supply a number of elements greater than the format maximum of eight. The OpenImageIO Cineon reader uses that unchecked value as a loop bound while filling a fixed eight-entry string array, writing pointers beyond the stack buffer and into adjacent memory, which results in memory corruption and a denial of service. This is a classic stack buffer overflow (CWE-121) that violates bounds checking (CWE-787).
Affected Systems
The vulnerable product is OpenImageIO from the Academy Software Foundation. Versions released before 3.0.20.0, before 3.1.15.0, and before 3.2.0.3-beta1 are susceptible when the Cineon input plugin is present.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. EPSS score of 0.00198 indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, so public exploitation is uncertain. The likely attack vector involves a local attacker providing a malicious Cineon file to the application; remote exploitation would require additional means to deliver such a file.
OpenCVE Enrichment