CVE-2020-15304NULL Pointer Dereference in Openexr

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 68.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 24

Description

An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDopenexr/openexr< 2.5.2
Debianopenexr/openexr< 2.5.3-2+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Fedora 31, 32

🔴Vulnerability Details

3
GHSA
GHSA-9rrf-xw5h-f29c: An issue was discovered in OpenEXR before 22022-05-24
CVEList
CVE-2020-15304: An issue was discovered in OpenEXR before 22020-06-26
OSV
CVE-2020-15304: An issue was discovered in OpenEXR before 22020-06-26

📋Vendor Advisories

2
Red Hat
OpenEXR: An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp2020-06-26
Debian
CVE-2020-15304: openexr - An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file cou...2020

💬Community

3
Bugzilla
CVE-2020-15304 mingw-OpenEXR: OpenEXR: An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp [fedora-all]2020-06-29
Bugzilla
CVE-2020-15304 OpenEXR: An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp2020-06-29
Bugzilla
CVE-2020-15304 OpenEXR: An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp [fedora-all]2020-06-29
CVE-2020-15304 — NULL Pointer Dereference in Openexr | cvebase