An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
A function returns the address of a stack variable, which will cause unintended program behavior, typically in the form of a crash.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openimageio | Openimageio | 2.4.4.2 (including) | 2.4.4.2 (including) |
Openimageio | Ubuntu | bionic | * |
Openimageio | Ubuntu | kinetic | * |
Openimageio | Ubuntu | lunar | * |
Openimageio | Ubuntu | mantic | * |
Openimageio | Ubuntu | trusty | * |
Openimageio | Ubuntu | xenial | * |