Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-43596

Опубликовано: 22 дек. 2022
Источник: debian
EPSS Низкий

Описание

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openimageiofixed2.4.7.1+dfsg-2package

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1654

  • https://github.com/OpenImageIO/oiio/pull/3676

EPSS

Процентиль: 39%
0.00175
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 5.9
nvd
больше 2 лет назад

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 5.9
github
больше 2 лет назад

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 5.9
fstec
почти 3 года назад

Уязвимость компонента iffoutput библиотеки обработки изображений OpenImageIO, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 39%
0.00175
Низкий