CVE-2022-43596: Medium severity openimageio vulnerability
An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43596?
CVE-2022-43596 is an information disclosure vulnerability in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
How does CVE-2022-43596 occur?
CVE-2022-43596 occurs due to an issue in the ImageOutput Object of OpenImageIO, where a specially crafted object can lead to leaked heap data.
What is the impact of CVE-2022-43596?
The impact of CVE-2022-43596 is that an attacker can provide malicious input to trigger the vulnerability and potentially obtain sensitive information.
Which versions of OpenImageIO are affected by CVE-2022-43596?
The affected versions of OpenImageIO are 2.0.5~dfsg0-1+deb10u2, 2.2.10.1+dfsg-1+deb11u1, 2.4.7.1+dfsg-2, and 2.4.13.0+dfsg-1.
How can I fix CVE-2022-43596?
To fix CVE-2022-43596, update OpenImageIO to a version that is not affected. Refer to the official Debian source for the remediation steps.