CVE-2022-43594

NameCVE-2022-43594
DescriptionMultiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3382-1, DSA-5384-1, ELA-846-1
Debian Bugs1027143

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openimageio (PTS)jessie, jessie (lts)1.4.14~dfsg0-1+deb8u2fixed
stretch (lts), stretch1.6.17~dfsg0-1+deb9u1fixed
buster (security), buster, buster (lts)2.0.5~dfsg0-1+deb10u2fixed
bullseye (security), bullseye2.2.10.1+dfsg-1+deb11u1fixed
bookworm2.4.7.1+dfsg-2fixed
sid2.5.15.0+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openimageiosourcejessie1.4.14~dfsg0-1+deb8u1ELA-846-1
openimageiosourcestretch1.6.17~dfsg0-1+deb9u1ELA-846-1
openimageiosourcebuster2.0.5~dfsg0-1+deb10u1DLA-3382-1
openimageiosourcebullseye2.2.10.1+dfsg-1+deb11u1DSA-5384-1
openimageiosource(unstable)2.4.7.1+dfsg-21027143

Notes

https://talosintelligence.com/vulnerability_reports/TALOS-2022-1653
https://github.com/OpenImageIO/oiio/pull/3673

Search for package or bug name: Reporting problems