Skip to content

Commit 722c7f4

Browse files
committed
security: Document CVE-2024-40630 resolution
Signed-off-by: Larry Gritz <lg@larrygritz.com>
1 parent 5cc8860 commit 722c7f4

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,8 @@ None known
3434

3535
Most recent fixes listed first, more or less
3636

37+
- CVE-2024-40630: Fixed incorrect image size for certain HEIC files.
38+
[advisory](https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-jjm9-9m4m-c8p2) (Fixed in 2.5.13.1)
3739
- CVE-2023-42295: Fix signed integer overflow when computing total number of pixels while reading BMP files. [#3948](https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/3948) (by xiaoxiaoafeifei) (Fixed in 2.5.3.0/2.6.0.1)
3840
- CVE-2023-36183: Heap-buffer-overflow while reading ICO files [#3872](https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/3872) (by xiaoxiaoafeifei)
3941
- TALOS-2023-1709 / CVE-2023-24472: Race condition in TIFF reader. [#3772](https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/3772) (2.5.1.0/2.4.8.1)

0 commit comments

Comments
 (0)