PT-2022-8496 · Pixar · Pixar Openusd
Aleksandar Nikolic
·
Published
2022-04-18
·
Updated
2022-04-26
·
CVE-2020-13495
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pixar OpenUSD version 20.05
Description
A vulnerability exists in the way Pixar OpenUSD handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access, potentially leading to the disclosure of sensitive information. This issue could be used to bypass mitigations and aid additional exploitation. The victim needs to access an attacker-provided file to trigger the vulnerability.
Recommendations
For Pixar OpenUSD version 20.05, avoid accessing files from untrusted sources until a patch is available. As a temporary workaround, consider restricting access to files that could potentially trigger the out-of-bounds memory access.
Exploit
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pixar Openusd