PT-2020-6206 · Ilmbase+4 · Openexr+4

Arnow117

·

Published

2020-06-26

·

Updated

2022-09-02

·

CVE-2020-15305

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions prior to 2.5.2
Description An issue in OpenEXR is related to the use of memory after it has been freed, specifically in the DeepScanLineInputFile::DeepScanLineInputFile() function. This can be caused by invalid input and may lead to a denial of service. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations For versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the DeepScanLineInputFile::DeepScanLineInputFile() function until a patch is available.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3135
ALT-PU-2020-3136
ALT-PU-2021-1312
ALT-PU-2021-1313
AZL-44481
BDU:2021-03551
CVE-2020-15305
DLA-2358-1
DSA-4755-1
MGASA-2021-0015
OESA-2021-1268
OPENSUSE-SU-2020:0970-1
OPENSUSE-SU-2020:1015-1
OPENSUSE-SU-2020_0970-1
OPENSUSE-SU-2020_1015-1
SUSE-SU-2020:1931-1
SUSE-SU-2020:1984-1
USN-4418-1

Affected Products

Alt Linux
Linuxmint
Openexr
Suse
Ubuntu