Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Peter Hillman

#45361of 53,633
5.5Total CVSS
Vulnerabilities · 1
PT-2020-14344
5.5
2020-06-26
Ilm · Openexr · CVE-2020-15304
**Name of the Vulnerable Software and Affected Versions** OpenEXR versions prior to 2.5.2 **Description** An issue was discovered where an invalid tiled input file could cause invalid memory access in `TiledInputFile::TiledInputFile()` in `IlmImf/ImfTiledInputFile.cpp`, as demonstrated by a NULL pointer dereference. **Recommendations** For OpenEXR versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider validating all tiled input files to prevent invalid memory access.