PT-2019-6170 · Tinyexr · Tinyexr

Chijinz

·

Published

2019-03-05

·

Updated

2021-08-03

·

CVE-2020-18430

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions tinyexr version 0.9.5
Description The issue is related to an array index error in the tinyexr::DecodeEXRImage component of the tinyexr library for image processing. This error can be exploited by a remote attacker to cause a denial of service.
Recommendations For tinyexr version 0.9.5, consider disabling the tinyexr::DecodeEXRImage component until a patch is available to prevent potential denial of service attacks.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01655
CVE-2020-18430

Affected Products

Tinyexr