CVE-2022-41837

An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openimageio:openimageio:2.4.4.2:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:23

Type Values Removed Values Added
References () https://lists.debian.org/debian-lts-announce/2023/08/msg00005.html - () https://lists.debian.org/debian-lts-announce/2023/08/msg00005.html -
References () https://security.gentoo.org/glsa/202305-33 - () https://security.gentoo.org/glsa/202305-33 -
References () https://talosintelligence.com/vulnerability_reports/TALOS-2022-1636 - Exploit, Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2022-1636 - Exploit, Third Party Advisory
References () https://www.debian.org/security/2023/dsa-5384 - Third Party Advisory () https://www.debian.org/security/2023/dsa-5384 - Third Party Advisory
Summary
  • (es) Existe una vulnerabilidad de escritura fuera de los límites en la funcionalidad OpenImageIO::add_exif_item_to_spec de OpenImageIO Project OpenImageIO v2.4.4.2. Los metadatos exif especialmente manipulados pueden provocar corrupción en la región stack de la memoria. Un atacante puede proporcionar un archivo malicioso para desencadenar esta vulnerabilidad.

Information

Published : 2022-12-22 22:15

Updated : 2024-11-21 07:23


NVD link : CVE-2022-41837

Mitre link : CVE-2022-41837

CVE.ORG link : CVE-2022-41837


JSON object : View

Products Affected

debian

  • debian_linux

openimageio

  • openimageio
CWE
CWE-562

Return of Stack Variable Address

CWE-787

Out-of-bounds Write