PT-2020-13572 · Pixar · Pixar Openusd

Published

2020-12-02

·

Updated

2022-10-05

·

CVE-2020-13494

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pixar OpenUSD version 20.05
Description A heap overflow issue exists in the parsing of compressed string tokens in binary USD files. This can be triggered by a specially crafted malformed file, leading to out of bounds memory access and potentially resulting in information disclosure. The issue could be used to bypass mitigations and aid in further exploitation. It is triggered when a victim accesses an attacker-provided malformed file.
Recommendations For Pixar OpenUSD version 20.05, consider avoiding the use of compressed string tokens in binary USD files until a patch is available. As a temporary workaround, restrict access to potentially malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2020-13494

Affected Products

Pixar Openusd