CVE-2022-43594NULL Pointer Dereference in Openimageio

Severity
5.9MEDIUMNVD
EPSS
0.1%
top 65.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateMar 30

Description

Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/openimageio< openimageio 2.4.7.1+dfsg-2 (bookworm)
Debianopenimageio/openimageio< 2.2.10.1+dfsg-1+deb11u1+3

Also affects: Debian Linux 11.0

🔴Vulnerability Details

2
GHSA
GHSA-wv3j-w28p-m9x9: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v22022-12-23
OSV
CVE-2022-43594: Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v22022-12-22

📋Vendor Advisories

1
Debian
CVE-2022-43594: openimageio - Multiple denial of service vulnerabilities exist in the image output closing fun...2022

🕵️Threat Intelligence

4
Talos
Vulnerability Spotlight: Specially crafted files could lead to denial of service, information disclosure in OpenImageIO parser2023-03-30
Talos
Vulnerability Spotlight: Specially crafted files could lead to denial of service, information disclosure in OpenImageIO parser2023-03-30
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service2022-12-22
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service2022-12-22