PT-2019-6170 · Tinyexr · Tinyexr
Chijinz
·
Published
2019-03-05
·
Updated
2021-08-03
·
CVE-2020-18430
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
tinyexr version 0.9.5
Description
The issue is related to an array index error in the
tinyexr::DecodeEXRImage component of the tinyexr library for image processing. This error can be exploited by a remote attacker to cause a denial of service.Recommendations
For tinyexr version 0.9.5, consider disabling the
tinyexr::DecodeEXRImage component until a patch is available to prevent potential denial of service attacks.Exploit
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tinyexr