CVE-2025-15506

Source
https://cve.org/CVERecord?id=CVE-2025-15506
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15506.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15506
Aliases
Downstream
Published
2026-01-11T11:15:49.113Z
Modified
2026-01-15T05:51:11.224009Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named ebdbb75123c9d5f4643e041314e2bc988a13f20d. To fix this issue, it is recommended to deploy a patch. The fix was added to the 2.5.1 milestone.

References

Affected packages

Git / github.com/cozdas/opencolorio

Affected ranges

Type
GIT
Repo
https://github.com/cozdas/opencolorio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.5.10
v0.5.11
v0.5.12
v0.5.13
v0.5.14
v0.5.15
v0.5.16
v0.5.8
v0.5.9
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.7.9
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.8.6
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.1.0
v2.*
v2.0.0-beta1
v2.0.0-beta2
v2.0.0-rc1
v2.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15506.json"
vanir_signatures
[
    {
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/cozdas/opencolorio/commit/ebdbb75123c9d5f4643e041314e2bc988a13f20d",
        "digest": {
            "line_hashes": [
                "196940627908718943272715626648468933299",
                "161115911433970871594422040431130875992",
                "36357636186734676598214840189756014168",
                "188427166458745316299655894993446518452"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-15506-7ecea021",
        "deprecated": false,
        "target": {
            "file": "src/OpenColorIO/FileRules.cpp"
        }
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/cozdas/opencolorio/commit/ebdbb75123c9d5f4643e041314e2bc988a13f20d",
        "digest": {
            "function_hash": "245335890381862967525355425868078544686",
            "length": 2392.0
        },
        "id": "CVE-2025-15506-a0ca7350",
        "deprecated": false,
        "target": {
            "file": "src/OpenColorIO/FileRules.cpp",
            "function": "ConvertToRegularExpression"
        }
    }
]