CVE-2022-43594
Summary
| CVE | CVE-2022-43594 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 22:15:00 UTC |
| Updated | 2024-02-01 17:06:00 UTC |
| Description | Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| TALOS-2022-1653 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence |
MISC |
talosintelligence.com |
|
| OpenImageIO: Multiple Vulnerabilities (GLSA 202305-33) — Gentoo security |
MISC |
security.gentoo.org |
|
| Debian -- Security Information -- DSA-5384-1 openimageio |
MISC |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181695 Debian Security Update for openimageio (DLA 3382-1)
- 181726 Debian Security Update for openimageio (DSA 5384-1)
- 183009 Debian Security Update for openimageio (CVE-2022-43594)
- 710740 Gentoo Linux OpenImageIO Multiple Vulnerabilities (GLSA 202305-33)