CVE-2022-43593: Null Pointer Dereference
Published Dec 22, 2022
·Updated
A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability.
Affected Software
3 affected componentsFixes available
debian/openimageio<=2.0.5~dfsg0-1
2.0.5~dfsg0-1+deb10u22.2.10.1+dfsg-1+deb11u12.4.7.1+dfsg-22.4.14.0+dfsg-1
Openimageio Openimageio=2.4.4.2
Debian Debian Linux=11.0
Event History
Dec 22, 2022
CVE Published
10:15 PM
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 23, 2022
CVE Published
via MITRE·11:03 PM
Data Sourced
via MITRE·11:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this denial of service vulnerability?
The vulnerability ID for this denial of service vulnerability is CVE-2022-43593.
2
What is the severity rating of CVE-2022-43593?
CVE-2022-43593 has a severity rating of 5.9, which is considered medium.
3
Which software is affected by CVE-2022-43593?
OpenImageIO Project OpenImageIO version 2.4.4.2 and Debian Debian Linux version 11.0 are affected by CVE-2022-43593.
4
What is the impact of CVE-2022-43593?
CVE-2022-43593 can lead to null pointer dereference, causing a denial of service.
5
Are there any recommended remedies for CVE-2022-43593?
Yes, updating to Openimageio version 2.4.7.1+dfsg-2 or higher can remediate CVE-2022-43593.