Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41684


A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.


Published

2022-12-22T22:15:14.760

Last Modified

2024-11-21T07:23:38.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-125
  • Type: Secondary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openimageio openimageio 2022-09-14 Yes

References