CVE-2022-43596Out-of-bounds Read in Openimageio

CWE-125Out-of-bounds Read6 documents5 sources
Severity
5.9MEDIUMNVD
EPSS
0.2%
top 59.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateDec 23

Description

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/openimageio< openimageio 2.4.7.1+dfsg-2 (bookworm)
Debianopenimageio/openimageio< 2.2.10.1+dfsg-1+deb11u1+3

Also affects: Debian Linux 11.0

🔴Vulnerability Details

2
GHSA
GHSA-xwhj-x2g6-527m: An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v22022-12-23
OSV
CVE-2022-43596: An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v22022-12-22

📋Vendor Advisories

1
Debian
CVE-2022-43596: openimageio - An information disclosure vulnerability exists in the IFFOutput channel interlea...2022

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service2022-12-22
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service2022-12-22