PT-2022-6803 · Unknown+2 · Openimageio+2
Lilith >_>
·
Published
2022-10-19
·
Updated
2025-06-23
·
CVE-2022-41988
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenImageIO version 2.3.19.0
Description
An information disclosure issue exists in the OpenImageIO::decode iptc iim() functionality. This is related to reading beyond the valid boundaries of a data buffer. A specially-crafted TIFF file can lead to the disclosure of sensitive information. An attacker can provide a malicious file to trigger this issue.
Recommendations
For version 2.3.19.0, consider disabling the
decode iptc iim() function until a patch is available to prevent exploitation.
At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Openimageio