Impact
OpenImageIO, a widely used image processing library, has a signed integer overflow in the conversion from TGA to GIF images. A truncated TGA file triggers the gifsplitpalette() routine, where the product computes a pixel count multiplied by a palette width using signed 32‑bit arithmetic. The overflow corrupts internal structures and results in an out‑of‑bounds read during the creation of the GIF palette, causing a segmentation fault and terminating the process. The impact is a denial‑of‑service condition when the vulnerable library processes malicious input.
Affected Systems
The vulnerability affects Academy Software Foundation’s OpenImageIO version entries prior to 3.0.21.0, 3.1.16.0, and the pre‑release 3.2.0.3-beta1. Any deployment that still uses those releases and processes TGA images is potentially susceptible.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the moderate severity range. The EPSS score is less than 1%, indicating a low exploitation probability. The vulnerability has not been listed in CISA’s KEV catalog. While no proven exploit is disclosed, the known attack involves supplying a crafted TGA file that triggers a crash during image conversion. No additional network access requirements are stated, so the likely attack vector is the ingestion of a malicious TGA file by a local or remote image processing workflow.
OpenCVE Enrichment