PT-2022-8496 · Pixar · Pixar Openusd

Aleksandar Nikolic

·

Published

2022-04-18

·

Updated

2022-04-26

·

CVE-2020-13495

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pixar OpenUSD version 20.05
Description A vulnerability exists in the way Pixar OpenUSD handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access, potentially leading to the disclosure of sensitive information. This issue could be used to bypass mitigations and aid additional exploitation. The victim needs to access an attacker-provided file to trigger the vulnerability.
Recommendations For Pixar OpenUSD version 20.05, avoid accessing files from untrusted sources until a patch is available. As a temporary workaround, consider restricting access to files that could potentially trigger the out-of-bounds memory access.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13495

Affected Products

Pixar Openusd