CVE-2022-43597Heap-based Buffer Overflow in Openimageio

Severity
8.1HIGHNVD
EPSS
0.5%
top 36.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateDec 23

Description

Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to arbitrary code execution. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `m_spec.format` is `TypeDesc::UINT8`.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

debiandebian/openimageio< openimageio 2.4.7.1+dfsg-2 (bookworm)
Debianopenimageio/openimageio< 2.2.10.1+dfsg-1+deb11u1+3

Also affects: Debian Linux 11.0

🔴Vulnerability Details

2
GHSA
GHSA-m8q3-f9r8-5rqr: Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v22022-12-23
OSV
CVE-2022-43597: Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v22022-12-22

📋Vendor Advisories

1
Debian
CVE-2022-43597: openimageio - Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padd...2022

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service2022-12-22
Talos
Vulnerability Spotlight: OpenImageIO file processing issues could lead to arbitrary code execution, sensitive information leak and denial of service2022-12-22