CVE-2022-38143

A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:openimageio:openimageio:2.3.19.0:*:*:*:*:*:*:*

History

01 Feb 2024, 18:02

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de escritura fuera de los límites en la forma en que OpenImageIO v2.3.19.0 procesa imágenes BMP codificadas con RLE. Un archivo bmp especialmente manipulado puede escribir en una memoria arbitraria fuera de los límites, lo que puede provocar la ejecución de código arbitrario. Un atacante puede proporcionar un archivo malicioso para desencadenar esta vulnerabilidad.
References () https://security.gentoo.org/glsa/202305-33 - () https://security.gentoo.org/glsa/202305-33 - Third Party Advisory

30 May 2023, 06:15

Type Values Removed Values Added
References
  • (MISC) https://security.gentoo.org/glsa/202305-33 -
CWE CWE-787 CWE-123

15 May 2023, 16:07

Type Values Removed Values Added
CPE cpe:2.3:a:openimageio_project:openimageio:2.3.19.0:*:*:*:*:*:*:* cpe:2.3:a:openimageio:openimageio:2.3.19.0:*:*:*:*:*:*:*
First Time Openimageio
Openimageio openimageio

28 Feb 2023, 18:35

Type Values Removed Values Added
CPE cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

01 Feb 2023, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3LET4MEPBSBJZK4EMLEBY4FUXKU5BMN/', 'name': 'FEDORA-2022-e63bc3eca2', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}

06 Jan 2023, 14:11

Type Values Removed Values Added
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3LET4MEPBSBJZK4EMLEBY4FUXKU5BMN/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3LET4MEPBSBJZK4EMLEBY4FUXKU5BMN/ - Mailing List, Third Party Advisory
First Time Fedoraproject
Fedoraproject fedora
CPE cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
CWE CWE-123 CWE-787

31 Dec 2022, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3LET4MEPBSBJZK4EMLEBY4FUXKU5BMN/ -

30 Dec 2022, 01:53

Type Values Removed Values Added
References (MISC) https://talosintelligence.com/vulnerability_reports/TALOS-2022-1630 - (MISC) https://talosintelligence.com/vulnerability_reports/TALOS-2022-1630 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:openimageio_project:openimageio:2.3.19.0:*:*:*:*:*:*:*
First Time Openimageio Project
Openimageio Project openimageio

22 Dec 2022, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-22 22:15

Updated : 2024-02-01 18:02


NVD link : CVE-2022-38143

Mitre link : CVE-2022-38143

CVE.ORG link : CVE-2022-38143


JSON object : View

Products Affected

openimageio

  • openimageio
CWE
CWE-123

Write-what-where Condition

CWE-787

Out-of-bounds Write