NULL pointer dereference in oiio - CVE-2022-43594
Published: April 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the image output closing functionality that applies to writing .bmp files. A remote attacker can trick the victim to open a specially crafted file and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Gentoo Linux
openimageio (Debian package)
media-libs/openimageio
How to mitigate CVE-2022-43594
openimageio (Debian package) - update to 2.2.10.1+dfsg-1+deb11u1
media-libs/openimageio - update to 2.4.6.0