CVE-2022-41794: Buffer Overflow
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41794?
CVE-2022-41794 is a heap based buffer overflow vulnerability in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0.
How does CVE-2022-41794 impact OpenImageIO?
CVE-2022-41794 can lead to arbitrary code execution if a specially-crafted PSD file is provided to OpenImageIO.
How severe is CVE-2022-41794?
CVE-2022-41794 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2022-41794?
OpenImageIO version 2.3.19.0 is affected by CVE-2022-41794.
How can I mitigate the CVE-2022-41794 vulnerability?
To mitigate the CVE-2022-41794 vulnerability, it is recommended to update to a patched version of OpenImageIO or apply the necessary security patches provided by the vendor.