Description
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
Published: 2022-12-23
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3382-1 openimageio security update
Debian DSA Debian DSA DSA-5384-1 openimageio security update
EUVD EUVD EUVD-2022-46590 Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00101}

epss

{'score': 0.00133}


Subscriptions

Debian Debian Linux
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2025-02-13T16:33:30.505Z

Reserved: 2022-10-21T00:00:00.000Z

Link: CVE-2022-43594

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-22T22:15:16.227

Modified: 2024-11-21T07:26:50.680

Link: CVE-2022-43594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses