CVE-2020-11765
published 2020-04-14CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.70%
74.8th percentile
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.20 | 7.20 |
| apple | icloud | >= 10.0 < 11.3 | 11.3 |
| apple | ios_13.6_and_ipados | — | — |
| apple | ipados | < 13.6 | 13.6 |
| apple | iphone_os | < 13.6 | 13.6 |
| apple | itunes | < 12.10.8 | 12.10.8 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.13.0 < 10.13.6 | 10.13.6 |
| apple | mac_os_x | >= 10.14.0 < 10.14.6 | 10.14.6 |
| apple | mac_os_x | >= 10.15 < 10.15.6 | 10.15.6 |
| apple | macos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004 | — | — |
| apple | tvos | < 13.4.8 | 13.4.8 |
| apple | tvos | — | — |
| apple | watchos | < 6.2.8 | 6.2.8 |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openexr | < openexr 2.5.3-2 (bookworm) | openexr 2.5.3-2 (bookworm) |
| fedoraproject | fedora | — | — |
| openexr | openexr | < 2.4.1 | 2.4.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rhrf-xrq9-3h4h: An issue was discovered in OpenEXR before 2
ghsa_unreviewed·2022-05-24
CVE-2020-11765 [MEDIUM] CWE-125 GHSA-rhrf-xrq9-3h4h: An issue was discovered in OpenEXR before 2
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
OSV
openexr vulnerabilities
osv·2020-04-27·CVSS 8.8
CVE-2017-9111 [HIGH] openexr vulnerabilities
openexr vulnerabilities
Brandon Perry discovered that OpenEXR incorrectly handled certain malformed
EXR image files. If a user were tricked into opening a crafted EXR image
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 20.04 LTS.
(CVE-2017-9111, CVE-2017-9113, CVE-2017-9115)
Tan Jie discovered that OpenEXR incorrectly handled certain malformed EXR
image files. If a user were tricked into opening a crafted EXR image file,
a remote attacker could cause a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 20.04 LTS.
(CVE-2018-18444)
Samuel Groß discovered that OpenEXR incorrectly handled certain malformed
EXR image files. If a user were tricked into opening a crafted EXR i
OSV
CVE-2020-11765: An issue was discovered in OpenEXR before 2
osv·2020-04-14·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765: An issue was discovered in OpenEXR before 2
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
Project0
Fuzzing ImageIO - Project Zero
project_zero·2020-04-01
CVE-2020-11758 Fuzzing ImageIO - Project Zero
Posted by Samuel Groß, Project Zero
This blog post discusses an old type of issue, vulnerabilities in image format parsers, in a new(er) context: on interactionless code paths in popular messenger apps. This research was focused on the Apple ecosystem and the image parsing API provided by it: the ImageIO framework. Multiple vulnerabilities in image parsing code were found, reported to Apple or the respective open source image library maintainers, and subsequently fixed. During this research, a lightweight and low-overhead guided fuzzing approach for closed source binaries was implemented and is released alongside this blogpost.
To reiterate an important point, the vulnerabilities described throughout this blog are reachable through popular messengers but are not part of their codebase.
Apple
CVE-2020-11765: iOS 13.6 and iPadOS 13.6
vendor_apple·2020-07-15·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-11765
Component: ImageIO
Impact: Multiple buffer overflow issues existed in openEXR
Description: Multiple issues in openEXR were addressed with improved checks.
Apple
CVE-2020-11765: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
vendor_apple·2020-07-15·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
Product: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra
CVE: CVE-2020-11765
Component: ImageIO
Impact: Multiple buffer overflow issues existed in openEXR
Description: Multiple issues in openEXR were addressed with improved checks.
Apple
CVE-2020-11765: tvOS 13.4.8
vendor_apple·2020-07-15·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765: tvOS 13.4.8
Apple Security Update: About the security content of tvOS 13.4.8
Product: tvOS
Version: 13.4.8
CVE: CVE-2020-11765
Component: ImageIO
Impact: Multiple buffer overflow issues existed in openEXR
Description: Multiple issues in openEXR were addressed with improved checks.
Apple
CVE-2020-11765: watchOS 6.2.8
vendor_apple·2020-07-15·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765: watchOS 6.2.8
Apple Security Update: About the security content of watchOS 6.2.8
Product: watchOS
Version: 6.2.8
CVE: CVE-2020-11765
Component: ImageIO
Impact: Multiple buffer overflow issues existed in openEXR
Description: Multiple issues in openEXR were addressed with improved checks.
Ubuntu
OpenEXR vulnerabilities
vendor_ubuntu·2020-04-27·CVSS 8.8
CVE-2017-9111 [HIGH] OpenEXR vulnerabilities
Title: OpenEXR vulnerabilities
Summary: Several security issues were fixed in OpenEXR.
Brandon Perry discovered that OpenEXR incorrectly handled certain malformed
EXR image files. If a user were tricked into opening a crafted EXR image
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 20.04 LTS.
(CVE-2017-9111, CVE-2017-9113, CVE-2017-9115)
Tan Jie discovered that OpenEXR incorrectly handled certain malformed EXR
image files. If a user were tricked into opening a crafted EXR image file,
a remote attacker could cause a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 20.04 LTS.
(CVE-2018-18444)
Samuel Groß discovered that OpenEXR incorrectly handled certain malformed
EXR
Red Hat
OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read
vendor_redhat·2020-02-08·CVSS 5.5
CVE-2020-11765 [MEDIUM] CWE-193 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read
OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
Statement: Red Hat Enterprise Linux 7 and prior are not affected by this flaw as they do not ship vulnerable versions of OpenEXR.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: OpenEXR (Red Hat Enterprise Linux 6) - Out of support scope
Package: OpenEXR (Red Hat Enterpr
Debian
CVE-2020-11765: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in...
vendor_debian·2020·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in...
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11765 hadoop: Potential information disclosure in Hadoop Web interfaces
bugzilla·2020-09-29·CVSS 7.5
CVE-2018-11765 [HIGH] CVE-2018-11765 hadoop: Potential information disclosure in Hadoop Web interfaces
CVE-2018-11765 hadoop: Potential information disclosure in Hadoop Web interfaces
Description:
When Kerberos authentication is enabled and SPNEGO through HTTP is not
enabled, any users can access some servlets without authentication.
Mitigation:
Users should upgrade to Apache Hadoop 2.10.0, 3.0.1 or upper. If you
are using the affected version of Apache Hadoop, you need to enable
SPNEGO through HTTP.
Versions affected:
3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5
Discussion:
External References:
https://seclists.org/oss-sec/2020/q3/198
---
Upstream patch:
https://github.com/apache/hadoop/commit/94b0df839d36cf5d5e927b3642566c67d0689474
---
In OpenShift Container Platform the hadoop-container uses Hadoop 3.1.1.redhat-00002 (hadoop 3.1.1 + patches).
Not affected by this fla
Bugzilla
CVE-2020-11765 mingw-OpenEXR: OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read [fedora-all]
bugzilla·2020-04-28·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765 mingw-OpenEXR: OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read [fedora-all]
CVE-2020-11765 mingw-OpenEXR: OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM cha
Bugzilla
CVE-2020-11765 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read [fedora-all]
bugzilla·2020-04-28·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read [fedora-all]
CVE-2020-11765 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bugzilla
CVE-2020-11765 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read
bugzilla·2020-04-28·CVSS 5.5
CVE-2020-11765 [MEDIUM] CVE-2020-11765 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read
CVE-2020-11765 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
References:
https://bugs.chromium.org/p/project-zero/issues/detail?id=1987
https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md#version-241-february-11-2020
Discussion:
Created OpenEXR tracking bugs for this issue:
Affects: fedora-all [bug 1828986]
Created mingw-OpenEXR tracking bugs for this issue:
Affects: fedora-all [bug 1828987]
---
Upstream patch: https://github.com/AcademySoftwareFoundation/openexr/commit/3eda5d70aba127bae9bd
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00051.htmlhttps://bugs.chromium.org/p/project-zero/issues/detail?id=1987https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md#version-241-february-11-2020https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1https://lists.debian.org/debian-lts-announce/2020/08/msg00056.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F4KFGDQG5PVYAU7TS5MZ7XCS6EMPVII3/https://security.gentoo.org/glsa/202107-27https://support.apple.com/kb/HT211288https://support.apple.com/kb/HT211289https://support.apple.com/kb/HT211290https://support.apple.com/kb/HT211291https://support.apple.com/kb/HT211293https://support.apple.com/kb/HT211294https://support.apple.com/kb/HT211295https://usn.ubuntu.com/4339-1/https://www.debian.org/security/2020/dsa-4755http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00051.htmlhttps://bugs.chromium.org/p/project-zero/issues/detail?id=1987https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md#version-241-february-11-2020https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1https://lists.debian.org/debian-lts-announce/2020/08/msg00056.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F4KFGDQG5PVYAU7TS5MZ7XCS6EMPVII3/https://security.gentoo.org/glsa/202107-27https://support.apple.com/kb/HT211288https://support.apple.com/kb/HT211289https://support.apple.com/kb/HT211290https://support.apple.com/kb/HT211291https://support.apple.com/kb/HT211293https://support.apple.com/kb/HT211294https://support.apple.com/kb/HT211295https://usn.ubuntu.com/4339-1/https://www.debian.org/security/2020/dsa-4755
2020-04-14
Published