Medium severity5.9NVD Advisory· Published Dec 22, 2022· Updated Jun 17, 2026
CVE-2022-43595
CVE-2022-43595
Description
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .fits files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:openimageio:openimageio:2.4.4.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openimageio:openimageio:2.4.4.2:*:*:*:*:*:*:*
- (no CPE)range: = 2.4.4.2
- OpenImageIO Project/OpenImageIOv5Range: v2.4.4.2
Patches
Vulnerability mechanics
References
3- talosintelligence.com/vulnerability_reports/TALOS-2022-1653nvdExploitThird Party Advisory
- www.debian.org/security/2023/dsa-5384nvdThird Party Advisory
- security.gentoo.org/glsa/202305-33nvd
News mentions
0No linked articles in our index yet.