VDB

CVE-2022-38143

CVE-2022-38143 PUBLISHED CVSS 9.800000190734863 CRITICAL

A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

EPSS 2.11% · 84.4th percentile

Risk Scores

CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.11%
84.4th percentile

Affected Products

VendorProductVersions
openimageioopenimageio2.3.19.0
OpenImageIO ProjectOpenImageIOmaster-branch-9aeece7a, v2.3.19.0

Timeline

  • Dec 22, 2022 CVE Published
  • Dec 23, 2022 EPSS Score
  • Dec 28, 2022 EPSS Score
  • Feb 2, 2023 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Feb 23, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 27, 2023 EPSS Score
  • Jun 7, 2023 EPSS Score
  • Jul 19, 2023 EPSS Score
  • Aug 29, 2023 EPSS Score
  • Nov 20, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›