Debian Package Tracker
Register | Log in
Subscribe

openimageio

Choose email to subscribe with

general
  • source: openimageio (main)
  • version: 2.5.19.1+dfsg-1
  • maintainer: Debian PhotoTools Maintainers (archive) (DMD)
  • uploaders: Matteo F. Vescovi [DMD]
  • arch: all any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.2.10.1+dfsg-1+deb11u1
  • o-o-sec: 2.2.10.1+dfsg-1+deb11u1
  • oldstable: 2.4.7.1+dfsg-2
  • stable: 2.5.18.0+dfsg-1
  • testing: 2.5.19.1+dfsg-1
  • unstable: 2.5.19.1+dfsg-1
versioned links
  • 2.2.10.1+dfsg-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.7.1+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.5.18.0+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.5.19.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libopenimageio-dev
  • libopenimageio-doc
  • libopenimageio2.5
  • openimageio-tools
  • python3-openimageio
action needed
A new upstream version is available: 3.1.9.0 high
A new upstream version 3.1.9.0 is available, you should consider packaging it.
Created: 2025-11-27 Last update: 2026-01-15 02:00
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2024-55192: OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).
  • CVE-2024-55193: OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
  • CVE-2024-55194: OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
Created: 2025-02-17 Last update: 2026-01-05 08:01
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2024-55192: OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).
  • CVE-2024-55193: OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
  • CVE-2024-55194: OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
Created: 2025-08-09 Last update: 2026-01-05 08:01
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-01-01 Last update: 2026-01-01 07:00
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2024-55192: (needs triaging) OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).
  • CVE-2024-55193: (needs triaging) OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
  • CVE-2024-55194: (needs triaging) OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-01-26 Last update: 2026-01-05 08:01
12 low-priority security issues in bookworm low

There are 12 open security issues in bookworm.

12 issues left for the package maintainer to handle:
  • CVE-2023-3430: (needs triaging) A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. This flaw allows a remote attacker to pass a specially crafted file to the application, which triggers a heap-based buffer overflow and could cause a crash, leading to a denial of service.
  • CVE-2023-22845: (needs triaging) An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
  • CVE-2023-24472: (needs triaging) A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide malicious input to trigger this vulnerability.
  • CVE-2023-24473: (needs triaging) An information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.
  • CVE-2023-36183: (needs triaging) Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.
  • CVE-2023-42295: (needs triaging) An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c
  • CVE-2023-42299: (needs triaging) Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.
  • CVE-2024-40630: (needs triaging) OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API with a feature set, scalability, and robustness needed for feature film production. In affected versions there is a bug in the heif input functionality of OpenImageIO. Specifically, in `HeifInput::seek_subimage()`. In the worst case, this can lead to an information disclosure vulnerability, particularly for programs that directly use the `ImageInput` APIs. This bug has been addressed in commit `0a2dcb4c` which is included in the 2.5.13.1 release. Users are advised to upgrade. There are no known workarounds for this issue.
  • CVE-2024-55192: (needs triaging) OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).
  • CVE-2024-55193: (needs triaging) OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
  • CVE-2024-55194: (needs triaging) OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
  • CVE-2024-55195: (needs triaging) An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (DoS) when the program to requests to allocate too much space.

You can find information about how to handle these issues in the security team's documentation.

Created: 2023-04-09 Last update: 2026-01-05 08:01
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.3 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-12-31 15:30
news
[rss feed]
  • [2026-01-06] openimageio 2.5.19.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-31] Accepted openimageio 2.5.19.1+dfsg-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-02-26] openimageio 2.5.18.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-16] Accepted openimageio 2.5.18.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2025-01-27] openimageio 2.5.16.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-25] Accepted openimageio 2.5.16.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2024-09-08] Accepted openimageio 2.5.15.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2024-08-11] Accepted openimageio 2.5.14.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2024-06-17] Accepted openimageio 2.5.12.0+dfsg-2 (source) into unstable (Matteo F. Vescovi)
  • [2024-06-15] Accepted openimageio 2.5.12.0+dfsg-1 (source) into experimental (Matteo F. Vescovi)
  • [2024-04-13] Accepted openimageio 2.5.10.1+dfsg-1 (source) into experimental (Matteo F. Vescovi)
  • [2024-03-26] openimageio REMOVED from testing (Debian testing watch)
  • [2024-02-29] Accepted openimageio 2.4.17.0+dfsg-1.1 (source) into unstable (Benjamin Drung)
  • [2024-01-20] openimageio 2.4.17.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-17] Accepted openimageio 2.5.7.0+dfsg-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Matteo F. Vescovi)
  • [2024-01-14] Accepted openimageio 2.4.17.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2023-11-04] openimageio 2.4.16.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-29] Accepted openimageio 2.4.16.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2023-08-18] openimageio 2.4.14.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-12] Accepted openimageio 2.4.14.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2023-08-06] Accepted openimageio 2.0.5~dfsg0-1+deb10u2 (source) into oldoldstable (Markus Koschany)
  • [2023-07-17] openimageio 2.4.13.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-02] Accepted openimageio 2.4.13.0+dfsg-1 (source) into unstable (Matteo F. Vescovi)
  • [2023-06-24] Accepted openimageio 2.4.12.0+dfsg-1 (source) into experimental (Matteo F. Vescovi)
  • [2023-04-16] Accepted openimageio 2.2.10.1+dfsg-1+deb11u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2023-04-10] Accepted openimageio 2.2.10.1+dfsg-1+deb11u1 (source) into stable-security (Debian FTP Masters) (signed by: Markus Koschany)
  • [2023-04-04] Accepted openimageio 2.0.5~dfsg0-1+deb10u1 (source) into oldstable (Markus Koschany)
  • [2023-03-12] Accepted openimageio 2.4.9.0+dfsg-1 (source) into experimental (Matteo F. Vescovi)
  • [2023-01-28] openimageio 2.4.7.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-01-22] Accepted openimageio 2.4.7.1+dfsg-2 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 3
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.5.19.1+dfsg-1build1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing