Vulnerabilities > CVE-2022-43596
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 1 |
References
- https://security.gentoo.org/glsa/202305-33
- https://security.gentoo.org/glsa/202305-33
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1654
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1654
- https://www.debian.org/security/2023/dsa-5384
- https://www.debian.org/security/2023/dsa-5384