CVE-2022-36354: Medium severity openimageio vulnerability
A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36354?
The severity of CVE-2022-36354 is medium with a severity value of 5.3.
How does the heap out-of-bounds read vulnerability in CVE-2022-36354 occur?
The heap out-of-bounds read vulnerability in CVE-2022-36354 occurs in the RLA format parser of OpenImageIO, specifically in the way run-length encoded byte spans are handled.
Which versions of OpenImageIO are affected by CVE-2022-36354?
OpenImageIO versions master-branch-9aeece7a and v2.3.19.0 are affected by CVE-2022-36354.
How can a malformed RLA file lead to the exploitation of CVE-2022-36354?
A malformed RLA file can lead to the exploitation of CVE-2022-36354 by triggering an out-of-bounds read of heap metadata.
Is there a fix available for CVE-2022-36354?
Yes, there are updated versions of OpenImageIO and Debian Linux available that address the vulnerability.