A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1652 | third party advisory exploit |
https://www.debian.org/security/2023/dsa-5384 | third party advisory |
https://security.gentoo.org/glsa/202305-33 |