Bugzilla – Bug 1211839
VUL-0: CVE-2022-43593: openimageio: denial of service in the DPXOutput:close()
Last modified: 2023-05-31 03:54:00 UTC
CVE-2022-43593 A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-43593 https://bugzilla.redhat.com/show_bug.cgi?id=2211102 https://www.cve.org/CVERecord?id=CVE-2022-43593 https://security-tracker.debian.org/tracker/DSA-5384-1 https://talosintelligence.com/vulnerability_reports/TALOS-2022-1652 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1027143 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1027808 https://security.gentoo.org/glsa/202305-33 https://www.debian.org/security/2023/dsa-5384
We are shipping OpenImageIO 2.4.8.1 which is not affected, closing.