Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j94m-6fwj-5pv8

Опубликовано: 23 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the xmax variable is set to 0xFFFF and m_spec.format is TypeDesc::UINT16

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the xmax variable is set to 0xFFFF and m_spec.format is TypeDesc::UINT16

EPSS

Процентиль: 71%
0.00664
Низкий

8.1 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 3 лет назад

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `xmax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT16`

CVSS3: 8.1
nvd
около 3 лет назад

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `xmax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT16`

CVSS3: 8.1
debian
около 3 лет назад

Multiple code execution vulnerabilities exist in the IFFOutput::close( ...

CVSS3: 8.1
fstec
около 3 лет назад

Уязвимость функции close() компонента iffoutput библиотеки обработки изображений OpenImageIO, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 71%
0.00664
Низкий

8.1 High

CVSS3

Дефекты

CWE-122