CVE-2022-41684: High severity openimageio vulnerability
A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41684?
CVE-2022-41684 is a heap out of bounds read vulnerability in OpenImageIO.
How does CVE-2022-41684 occur?
CVE-2022-41684 occurs when parsing the image file directory part of a PSD image file in OpenImageIO.
What is the impact of CVE-2022-41684?
CVE-2022-41684 can lead to denial of service by causing a read of arbitrary memory address.
Which software versions are affected by CVE-2022-41684?
OpenImageIO versions up to and including 2022-09-14 are affected, along with specific Debian versions of the openimageio package.
How can I mitigate CVE-2022-41684?
Update OpenImageIO to a version that includes the security fix, such as 2.0.5~dfsg0-1+deb10u2 or 2.2.10.1+dfsg-1+deb11u1.