CVE-2022-43594: Null Pointer Dereference
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43594?
CVE-2022-43594 is a vulnerability in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2, which can be exploited by providing malicious inputs to trigger null pointer dereferences and result in denial of service.
What is the severity of CVE-2022-43594?
The severity of CVE-2022-43594 is not specified in the provided information.
How can CVE-2022-43594 be exploited?
CVE-2022-43594 can be exploited by providing specially crafted ImageOutput Objects as inputs to trigger null pointer dereferences and cause denial of service.
Which versions of OpenImageIO are affected by CVE-2022-43594?
OpenImageIO v2.0.5~dfsg0-1, v2.2.10.1+dfsg-1, v2.4.7.1+dfsg-2, and v2.4.13.0+dfsg-1 are affected by CVE-2022-43594.
How can I fix CVE-2022-43594?
To fix CVE-2022-43594, update the OpenImageIO package to version 2.0.5~dfsg0-1+deb10u2, 2.2.10.1+dfsg-1+deb11u1, 2.4.7.1+dfsg-2, or 2.4.13.0+dfsg-1 or later, as recommended by Debian.