CVE-2020-16589Out-of-bounds Write in Openexr

Severity
5.5MEDIUMNVD
EPSS
0.5%
top 32.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateMay 24

Description

A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial of service via a crafted EXR file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/openexr< openexr 2.5.3-2 (bookworm)
Debianopenexr/openexr< 2.5.3-2+3
NVDopenexr/openexr2.3.0

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r5w4-rhqv-q6mv: A head-based buffer overflow exists in Academy Software Foundation OpenEXR 22022-05-24
OSV
CVE-2020-16589: A head-based buffer overflow exists in Academy Software Foundation OpenEXR 22020-12-09

📋Vendor Advisories

3
Ubuntu
OpenEXR vulnerabilities2021-01-05
Red Hat
OpenEXR: A heap-based buffer overflow in writeTileData in ImfTiledOutputFile.cpp could result in a DOS via a crafted EXR file2020-12-10
Debian
CVE-2020-16589: openexr - A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0...2020