Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 11: DSA-5384-1 Critical: OpenImageIO Denial Of Service

debian
Calendar Grey April 10, 2023
Debian Logo
Several security flaws in openimageio could result in application instability or unauthorized code execution. An update is strongly advised.
Multiple security vulnerabilities have been discovered in OpenImageIO, a library for reading and writing images

Summary

Multiple security vulnerabilities have been discovered in OpenImageIO, a
library for reading and writing images. Buffer overflows and out-of-bounds
read and write programming errors may lead to a denial of service
(application crash) or the execution of arbitrary code if a malformed image
file is processed.

For the stable distribution (bullseye), these problems have been fixed in
version 2.2.10.1+dfsg-1+deb11u1.

We recommend that you upgrade your openimageio packages.

For the detailed security status of openimageio please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/openimageio

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: openimageio
CVE ID: CVE-2022-36354 CVE-2022-41639 CVE-2022-41649 CVE-2022-41684

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here