CVE-2022-43592: Medium severity openimageio vulnerability
An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43592?
CVE-2022-43592 is an information disclosure vulnerability in the DPXOutput::close() functionality of OpenImageIO.
How severe is CVE-2022-43592?
CVE-2022-43592 has a severity rating of 5.9 (medium).
What is the affected software of CVE-2022-43592?
The affected software includes OpenImageIO Project OpenImageIO v2.4.4.2 and Debian Debian Linux 11.0.
How can CVE-2022-43592 be exploited?
An attacker can provide malicious input to the DPXOutput::close() function to trigger the information disclosure vulnerability in OpenImageIO.
Where can I find more information about CVE-2022-43592?
More information about CVE-2022-43592 can be found at the following references: [link1], [link2], [link3].