CVE Vulnerabilities

CVE-2022-41837

Return of Stack Variable Address

Published: Dec 22, 2022 | Modified: Aug 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

Weakness

A function returns the address of a stack variable, which will cause unintended program behavior, typically in the form of a crash.

Affected Software

Name Vendor Start Version End Version
Openimageio Openimageio 2.4.4.2 (including) 2.4.4.2 (including)
Openimageio Ubuntu bionic *
Openimageio Ubuntu kinetic *
Openimageio Ubuntu lunar *
Openimageio Ubuntu mantic *
Openimageio Ubuntu trusty *
Openimageio Ubuntu xenial *

Potential Mitigations

References