PT-2021-6506 · Tinyexr · Tinyexr

Chijinz

·

Published

2021-07-26

·

Updated

2021-08-03

·

CVE-2020-18428

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions tinyexr version 0.9.5
Description The issue is related to an array index error in the tinyexr::SaveEXR component of the OpenEXR Tinyexr library for image processing. This error can be exploited by a remote attacker to cause a denial of service (DOS).
Recommendations For version 0.9.5, consider disabling the tinyexr::SaveEXR component until a patch is available to prevent potential denial of service attacks.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01764
CVE-2020-18428

Affected Products

Tinyexr