CVE-2022-41837: Critical severity openimageio vulnerability
Published Dec 22, 2022
·Updated
An out-of-bounds write vulnerability exists in the OpenImageIO::addexifitemtospec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
3 affected componentsFixes available
debian/openimageio<=2.0.5~dfsg0-1
2.0.5~dfsg0-1+deb10u22.2.10.1+dfsg-1+deb11u12.4.7.1+dfsg-22.4.14.0+dfsg-1
Openimageio Openimageio=2.4.4.2
Debian Debian Linux=11.0
Event History
Dec 22, 2022
CVE Published
10:15 PM
Dec 23, 2022
CVE Published
via MITRE·11:03 PM
Data Sourced
via MITRE·11:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-41837?
CVE-2022-41837 is an out-of-bounds write vulnerability in OpenImageIO Project OpenImageIO v2.4.4.2.
2
How does CVE-2022-41837 affect OpenImageIO?
CVE-2022-41837 can lead to stack-based memory corruption in OpenImageIO.
3
What is the severity of CVE-2022-41837?
CVE-2022-41837 has a severity rating of critical with a CVSS score of 9.8.
4
Which software versions are affected by CVE-2022-41837?
OpenImageIO v2.4.4.2 and Debian Linux 11.0 are affected by CVE-2022-41837.
5
How can CVE-2022-41837 be fixed?
Apply the latest security updates provided by OpenImageIO and Debian to fix CVE-2022-41837.