CVE-2022-41639: Buffer Overflow
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
CVE-2022-41639
What is the severity of CVE-2022-41639?
The severity of CVE-2022-41639 is critical, with a CVSS score of 9.8.
What is the affected software for CVE-2022-41639?
The affected software for CVE-2022-41639 is OpenImageIO version 2.3.19.0 and Debian Linux version 11.0.
How does CVE-2022-41639 impact the system?
CVE-2022-41639 can lead to an out-of-bounds memory corruption, which can result in arbitrary code execution.
Are there any references for CVE-2022-41639?
Yes, you can find references for CVE-2022-41639 at the following links: 1. [Gentoo GLSA-202305-33](https://security.gentoo.org/glsa/202305-33) 2. [Talos Intelligence Vulnerability Report](https://talosintelligence.com/vulnerability_reports/TALOS-2022-1633) 3. [Debian Security Advisory DSA-5384](https://www.debian.org/security/2023/dsa-5384)