CVE-2022-41837
published 2022-12-22CVE-2022-41837: An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.58%
72.7th percentile
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openimageio | < openimageio 2.4.7.1+dfsg-2 (bookworm) | openimageio 2.4.7.1+dfsg-2 (bookworm) |
| openimageio | openimageio | — | — |
| openimageio | openimageio | >= 0 < 2.2.10.1+dfsg-1+deb11u1 | 2.2.10.1+dfsg-1+deb11u1 |
| openimageio | openimageio | >= 0 < 2.4.7.1+dfsg-2 | 2.4.7.1+dfsg-2 |
| openimageio | openimageio | >= 0 < 2.4.7.1+dfsg-2 | 2.4.7.1+dfsg-2 |
| openimageio | openimageio | >= 0 < 2.4.7.1+dfsg-2 | 2.4.7.1+dfsg-2 |
| openimageio_project | openimageio | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hg4-4q69-pf8q: An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2
ghsa_unreviewed·2022-12-23
CVE-2022-41837 [CRITICAL] CWE-562 GHSA-2hg4-4q69-pf8q: An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2022-41837: An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2
osv·2022-12-22·CVSS 9.8
CVE-2022-41837 [CRITICAL] CVE-2022-41837: An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Debian
CVE-2022-41837: openimageio - An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to...
vendor_debian·2022·CVSS 9.8
CVE-2022-41837 [CRITICAL] CVE-2022-41837: openimageio - An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to...
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.4.7.1+dfsg-2)
bullseye: resolved (fixed in 2.2.10.1+dfsg-1+deb11u1)
forky: resolved (fixed in 2.4.7.1+dfsg-2)
sid: resolved (fixed in 2.4.7.1+dfsg-2)
trixie: resolved (fixed in 2.4.7.1+dfsg-2)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
blogs_talos·2022-12-22·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
## Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
Cisco Talos recently discovered nineteen vulnerabilities in OpenImageIO, an image processing library, which could lead to sensitive information disclosure, denial of service and heap buffer overflows which could further lead to code execution.
OpenImageIO is an image processing library useful for conversion and processing, as well as image comparison. This library is utilized by 3D-processing software from AliceVision (including Meshroom) and is also used by Blender for reading Photoshop .psd files.
Vulnerabilities were found in the way OpenImageIO processed .tif, .psd, .dds and other files and metadata types.
Several of the vulnerabili
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
blogs_talos·2022-12-22·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
Cisco Talos recently discovered nineteen vulnerabilities in OpenImageIO, an image processing library, which could lead to sensitive information disclosure, denial of service and heap buffer overflows which could further lead to code execution.
OpenImageIO is an image processing library useful for conversion and processing, as well as image comparison. This library is utilized by 3D-processing software from AliceVision (including Meshroom) and is also used by Blender for reading Photoshop .psd files.
Vulnerabilities were found in the way OpenImageIO processed .tif, .psd, .dds and other files and metadata types.
Several of the vulnerabilities are rated CVSS 9.8, high priority arbitrary code execution risks.
- TALOS-2022-1626 (CVE-2022-41794)
- TALOS-2022-1630 (CVE-2022-38143)
- TALOS-202
https://lists.debian.org/debian-lts-announce/2023/08/msg00005.htmlhttps://security.gentoo.org/glsa/202305-33https://talosintelligence.com/vulnerability_reports/TALOS-2022-1636https://www.debian.org/security/2023/dsa-5384https://lists.debian.org/debian-lts-announce/2023/08/msg00005.htmlhttps://security.gentoo.org/glsa/202305-33https://talosintelligence.com/vulnerability_reports/TALOS-2022-1636https://www.debian.org/security/2023/dsa-5384
2022-12-22
Published