CVE-2022-43594
published 2022-12-22CVE-2022-43594: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted…
PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
1.27%
66.4th percentile
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openimageio | < openimageio 2.4.7.1+dfsg-2 (bookworm) | openimageio 2.4.7.1+dfsg-2 (bookworm) |
| openimageio | openimageio | — | — |
| openimageio | openimageio | >= 0 < 2.2.10.1+dfsg-1+deb11u1 | 2.2.10.1+dfsg-1+deb11u1 |
| openimageio | openimageio | >= 0 < 2.4.7.1+dfsg-2 | 2.4.7.1+dfsg-2 |
| openimageio | openimageio | >= 0 < 2.4.7.1+dfsg-2 | 2.4.7.1+dfsg-2 |
| openimageio | openimageio | >= 0 < 2.4.7.1+dfsg-2 | 2.4.7.1+dfsg-2 |
| openimageio_project | openimageio | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-43594: openimageio - Multiple denial of service vulnerabilities exist in the image output closing fun...
vendor_debian·2022·CVSS 5.9
CVE-2022-43594 [MEDIUM] CVE-2022-43594: openimageio - Multiple denial of service vulnerabilities exist in the image output closing fun...
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
Scope: local
bookworm: resolved (fixed in 2.4.7.1+dfsg-2)
bullseye: resolved (fixed in 2.2.10.1+dfsg-1+deb11u1)
forky: resolved (fixed in 2.4.7.1+dfsg-2)
sid: resolved (fixed in 2.4.7.1+dfsg-2)
trixie: resolved (fixed in 2.4.7.1+dfsg-2)
GHSA
GHSA-wv3j-w28p-m9x9: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2
ghsa_unreviewed·2022-12-23
CVE-2022-43594 [MEDIUM] CWE-476 GHSA-wv3j-w28p-m9x9: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
OSV
CVE-2022-43594: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2
osv·2022-12-22·CVSS 5.9
CVE-2022-43594 [MEDIUM] CVE-2022-43594: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Specially crafted files could lead to denial of service, information disclosure in OpenImageIO parser
blogs_talos·2023-03-30·CVSS 5.9
CVE-2023-24473 [MEDIUM] Vulnerability Spotlight: Specially crafted files could lead to denial of service, information disclosure in OpenImageIO parser
Lilith >_> of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered three vulnerabilities in the OpenImageIO image-parsing library that many popular pieces of 3-D rendering software use.
OpenImageIO is a library that converts, compares and processes various image files. Blender and AliceVision, two often used computer imaging services, utilize the library, among other software offerings.
Two of the vulnerabilities — TALOS-2023-1707 (CVE-2023-24473) and TALOS-2023-1708 (CVE-2023-22845) — could lead to the disclosure of sensitive information. An adversary could exploit these vulnerabilities by sending the target a specially crafted, malicious Targa (.tga) file.
TALOS-2023-1709 (CVE-2023-24472) is a denial-of-service vulnerability that is a continuation of TALOS-20
Talos
Vulnerability Spotlight: Specially crafted files could lead to denial of service, information disclosure in OpenImageIO parser
blogs_talos·2023-03-30·CVSS 5.9
[MEDIUM] Vulnerability Spotlight: Specially crafted files could lead to denial of service, information disclosure in OpenImageIO parser
## Vulnerability Spotlight: Specially crafted files could lead to denial of service, information disclosure in OpenImageIO parser
Lilith >_> of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered three vulnerabilities in the OpenImageIO image-parsing library that many popular pieces of 3-D rendering software use.
OpenImageIO is a library that converts, compares and processes various image files. Blender and AliceVision, two often used computer imaging services, utilize the library, among other software offerings.
Two of the vulnerabilities — TALOS-2023-1707 (CVE-2023-24473) and TALOS-2023-1708 (CVE-2023-22845) — could lead to the disclosure of sensitive information. An adversary could exploit these vulnerabilities by sending the target a specially crafted, mal
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
blogs_talos·2022-12-22·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
## Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
Cisco Talos recently discovered nineteen vulnerabilities in OpenImageIO, an image processing library, which could lead to sensitive information disclosure, denial of service and heap buffer overflows which could further lead to code execution.
OpenImageIO is an image processing library useful for conversion and processing, as well as image comparison. This library is utilized by 3D-processing software from AliceVision (including Meshroom) and is also used by Blender for reading Photoshop .psd files.
Vulnerabilities were found in the way OpenImageIO processed .tif, .psd, .dds and other files and metadata types.
Several of the vulnerabili
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
blogs_talos·2022-12-22·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service
Cisco Talos recently discovered nineteen vulnerabilities in OpenImageIO, an image processing library, which could lead to sensitive information disclosure, denial of service and heap buffer overflows which could further lead to code execution.
OpenImageIO is an image processing library useful for conversion and processing, as well as image comparison. This library is utilized by 3D-processing software from AliceVision (including Meshroom) and is also used by Blender for reading Photoshop .psd files.
Vulnerabilities were found in the way OpenImageIO processed .tif, .psd, .dds and other files and metadata types.
Several of the vulnerabilities are rated CVSS 9.8, high priority arbitrary code execution risks.
- TALOS-2022-1626 (CVE-2022-41794)
- TALOS-2022-1630 (CVE-2022-38143)
- TALOS-202
https://security.gentoo.org/glsa/202305-33https://talosintelligence.com/vulnerability_reports/TALOS-2022-1653https://www.debian.org/security/2023/dsa-5384https://security.gentoo.org/glsa/202305-33https://talosintelligence.com/vulnerability_reports/TALOS-2022-1653https://www.debian.org/security/2023/dsa-5384
2022-12-22
Published