CVE-2020-13520Improper Restriction of Operations within the Bounds of a Memory Buffer in Openusd

Severity
7.8HIGHNVD
EPSS
0.9%
top 24.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 24

Description

An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A specially crafted malformed file can trigger an out of bounds memory modification which can result in remote code execution. To trigger this vulnerability, victim needs to access an attacker-provided malformed file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDpixar/openusd20.05
NVDapple/macos< 11.1

🔴Vulnerability Details

2
GHSA
GHSA-q84j-ghmc-vjvj: An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 202022-05-24
CVEList
CVE-2020-13520: An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 202020-12-11

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Pixar OpenUSD affects some versions of macOS2020-11-12
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Pixar OpenUSD affects some versions of macOS2020-11-12
CVE-2020-13520 — Pixar Openusd vulnerability | cvebase