Impact
OpenImageIO contains a heap‑buffer overread when reading an uncompressed 16‑bit iff image that also contains a z‑buffer. The code allocates a temporary scanline based on the number of RGBA channels but copies data using a stride that includes the z‑buffer bytes, causing memcpy to read beyond the allocated buffer. This flaw is identified as CWE‑125 and can lead to a crash or disclosure of adjacent heap memory. The impact is a local memory disclosure or denial of service if an attacker controls the image file.
Affected Systems
The vulnerability affects the AcademySoftwareFoundation OpenImageIO library prior to release versions 3.0.20.0, 3.1.15.0, and 3.2.0.3‑beta1.
Risk and Exploitability
The CVSS score is 6.1, indicating a moderate severity. The EPSS score is <1%, indicating a very low but non‑zero exploitation probability. The flaw is not listed in CISA's KEV catalog, and no exploits have been reported. Based on the description, it is inferred that a local or remote attacker could supply a crafted iff image to a system that runs OpenImageIO. An attacker could gain information disclosure or cause a denial‑of‑service condition by triggering the overread.
OpenCVE Enrichment