Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2023-0151 Critical: OpenImageIO Heap Out-Of-Bounds Issues

mageia
Calendar Grey April 24, 2023
Dist Mageia Esm H88
Mageia 2023-0151 tackles severe OpenImageIO security flaws, enhancing both system security and overall stability.
A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0

Summary

A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. (CVE-2022-36354)
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. (CVE-2022-38143)
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. (CVE-2022-41639)
A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file director...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=31364

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/T3LET4MEPBSBJZK4EMLEBY4FUXKU5BMN/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MLUXEL7AB2S5ACSDCHG67GEZHUYZBR5O/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/LK6TY36VQ3FQXMZ2VXHZGQ43VDLD67GG/

- https://lists.debian.org/debian-lts-announce/2023/04/msg00004.html

- https://lists.debian.org/debian-security-announce/2023/msg00074.html

- https://www.cve.org/CVERecord?id=CVE-2022-36354

- https://www.cve.org/CVERecord?id=CVE-2022-38143

- https://www.cve.org/CVERecord?id=CVE-2022-41639

- https://www.cve.org/CVERecord?id=CVE-2022-41684

- https://www.cve.org/CVERecord?id=CVE-2022-41794

- https://www.cve.org/CVERecord?id=CVE-2022-41838

- https://www.cve.org/CVERecord?id=CVE-2022-41977

- https://www.cve.org/CVERecord?id=CVE-2022-41981

- https://www.cve.org/CVERecord?id=CVE-2022-41988

- https://www.cve.org/CVERecord?id=CVE-2022-41999

- https://www.cve.org/CVERecord?id=CVE-2022-43592

- https://www.cve.org/CVERecord?id=CVE-2022-43593

- https://www.cve.org/CVERecord?id=CVE-2022-43594

- https://www.cve.org/CVERecord?id=CVE-2022-43595

- https://www.cve.org/CVERecord?id=CVE-2022-43596

- https://www.cve.org/CVERecord?id=CVE-2022-43597

- https://www.cve.org/CVERecord?id=CVE-2022-43598

- https://www.cve.org/CVERecord?id=CVE-2022-43599

- https://www.cve.org/CVERecord?id=CVE-2022-43600

- https://www.cve.org/CVERecord?id=CVE-2022-43601

- https://www.cve.org/CVERecord?id=CVE-2022-43602

- https://www.cve.org/CVERecord?id=CVE-2022-43603

- https://www.cve.org/CVERecord?id=CVE-2023-22845

- https://www.cve.org/CVERecord?id=CVE-2023-24472

- https://www.cve.org/CVERecord?id=CVE-2023-24473

Resolution

SRPMS

- 8/core/openimageio-2.2.10.0-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 Apr 2023
URL: https://advisories.mageia.org/MGASA-2023-0151.html
Type: security
CVE: CVE-2022-36354, CVE-2022-38143, CVE-2022-41639, CVE-2022-41684, CVE-2022-41794, CVE-2022-41838, CVE-2022-41977, CVE-2022-41981, CVE-2022-41988, CVE-2022-41999, CVE-2022-43592, CVE-2022-43593, CVE-2022-43594, CVE-2022-43595, CVE-2022-43596, CVE-2022-43597, CVE-2022-43598, CVE-2022-43599, CVE-2022-43600, CVE-2022-43601, CVE-2022-43602, CVE-2022-43603, CVE-2023-22845, CVE-2023-24472, CVE-2023-24473

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here