CVE-2020-13524
published 2020-12-03CVE-2020-13524: An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.82%
53.4th percentile
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_14.2_and_ipados | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.14.0 < 10.14.6 | 10.14.6 |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.1 | 11.1 |
| pixar | openusd | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8f9r-9957-fj34: An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20
ghsa_unreviewed·2022-05-24
CVE-2020-13524 [MEDIUM] CWE-119 GHSA-8f9r-9957-fj34: An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Apple
CVE-2020-13524: iOS 14.2 and iPadOS 14.2
vendor_apple·2020-11-05·CVSS 5.5
CVE-2020-13524 [MEDIUM] CVE-2020-13524: iOS 14.2 and iPadOS 14.2
Apple Security Update: About the security content of iOS 14.2 and iPadOS 14.2
Product: iOS 14.2 and iPadOS
Version: 14.2
CVE: CVE-2020-13524
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved input validation.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Pixar OpenUSD affects some versions of macOS
blogs_talos·2020-11-12
Vulnerability Spotlight: Multiple vulnerabilities in Pixar OpenUSD affects some versions of macOS
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities. Blog by Aleksandar Nikolic and Jon Munshaw.
Pixar OpenUSD contains multiple vulnerabilities that attackers could exploit to carry out a variety of malicious actions.
OpenUSD stands for “Open Universal Scene Descriptor.” Pixar uses this software for several types of animation tasks, including swapping arbitrary 3-D scenes that are composed of many different elements. Aimed at professional animation studios, the software is designed for scalability and speed as a pipeline connecting various aspects of the digital animation process. It is mostly expected to process trusted inputs in most use cases. This stands at odds with security considerations.
The USD file format itself is used as an interchange file format inside Appl
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Pixar OpenUSD affects some versions of macOS
blogs_talos·2020-11-12
Vulnerability Spotlight: Multiple vulnerabilities in Pixar OpenUSD affects some versions of macOS
## Vulnerability Spotlight: Multiple vulnerabilities in Pixar OpenUSD affects some versions of macOS
Aleksandar Nikolic of Cisco Talos discovered these vulnerabilities. Blog by Aleksandar Nikolic and Jon Munshaw.
Pixar OpenUSD contains multiple vulnerabilities that attackers could exploit to carry out a variety of malicious actions.
OpenUSD stands for “Open Universal Scene Descriptor.” Pixar uses this software for several types of animation tasks, including swapping arbitrary 3-D scenes that are composed of many different elements. Aimed at professional animation studios, the software is designed for scalability and speed as a pipeline connecting various aspects of the digital animation process. It is mostly expected to process trusted inputs in most use cases. This stands at odds with
http://seclists.org/fulldisclosure/2020/Dec/26http://seclists.org/fulldisclosure/2020/Dec/32https://support.apple.com/kb/HT212011https://talosintelligence.com/vulnerability_reports/TALOS-2020-1125http://seclists.org/fulldisclosure/2020/Dec/26http://seclists.org/fulldisclosure/2020/Dec/32https://support.apple.com/kb/HT212011https://talosintelligence.com/vulnerability_reports/TALOS-2020-1125
2020-12-03
Published