PT-2020-14344 · Ilm+2 · Openexr+2

Peter Hillman

·

Published

2020-06-26

·

Updated

2022-09-02

·

CVE-2020-15304

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions prior to 2.5.2
Description An issue was discovered where an invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
Recommendations For OpenEXR versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider validating all tiled input files to prevent invalid memory access.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3135
ALT-PU-2020-3136
ALT-PU-2021-1312
ALT-PU-2021-1313
AZL-45090
CVE-2020-15304
MGASA-2021-0015
OPENSUSE-SU-2020:0970-1
OPENSUSE-SU-2020:1015-1
OPENSUSE-SU-2020_0970-1
OPENSUSE-SU-2020_1015-1
SUSE-SU-2020:1931-1
SUSE-SU-2020:1984-1
SUSE-SU-2020_1931-1
SUSE-SU-2020_1984-1

Affected Products

Alt Linux
Openexr
Suse