Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-43594

Опубликовано: 22 дек. 2022
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openimageio:openimageio:2.4.4.2:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00188
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-476
CWE-476

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 3 лет назад

Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.

CVSS3: 5.9
debian
около 3 лет назад

Multiple denial of service vulnerabilities exist in the image output c ...

CVSS3: 5.9
github
около 3 лет назад

Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.

CVSS3: 5.9
fstec
около 3 лет назад

Уязвимость библиотеки обработки изображений OpenImageIO, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 41%
0.00188
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-476
CWE-476