First published: Tue Apr 14 2020(Updated: )
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
Credit: Xingwei Lin Ant cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13.4.8 | 13.4.8 |
macOS Catalina | <10.15.6 | 10.15.6 |
macOS Mojave | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Apple iCloud | <11.3 | 11.3 |
Apple iCloud | <7.20 | 7.20 |
iTunes | <12.10.8 | 12.10.8 |
Apple iOS and iPadOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and macOS | <13.6 | 13.6 |
debian/openexr | 2.5.4-2+deb11u1 3.1.5-5 3.1.13-2 | |
OpenEXR | <2.4.1 | |
Red Hat Fedora | =32 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 | |
Ubuntu | =20.04 | |
SUSE Linux | =15.1 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
iCloud for Windows | <7.20 | |
iCloud for Windows | >=11.0<11.3 | |
iTunes | <12.10.8 | |
Apple iOS, iPadOS, and macOS | <13.6 | |
iPhone OS | <13.6 | |
Apple iOS and macOS | <10.15.6 | |
Apple iOS and macOS | >=10.13.0<10.13.6 | |
Apple iOS and macOS | >=10.14.0<10.14.6 | |
Apple iOS and macOS | =10.13.6 | |
Apple iOS and macOS | =10.13.6-security_update_2018-002 | |
Apple iOS and macOS | =10.13.6-security_update_2018-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-001 | |
Apple iOS and macOS | =10.13.6-security_update_2019-002 | |
Apple iOS and macOS | =10.13.6-security_update_2019-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-004 | |
Apple iOS and macOS | =10.13.6-security_update_2019-005 | |
Apple iOS and macOS | =10.13.6-security_update_2019-006 | |
Apple iOS and macOS | =10.13.6-security_update_2019-007 | |
Apple iOS and macOS | =10.13.6-security_update_2020-001 | |
Apple iOS and macOS | =10.13.6-security_update_2020-002 | |
Apple iOS and macOS | =10.13.6-security_update_2020-003 | |
Apple iOS and macOS | =10.13.6-supplemental_update | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
Apple iOS and macOS | =10.14.6-security_update_2019-002 | |
Apple iOS and macOS | =10.14.6-security_update_2019-004 | |
Apple iOS and macOS | =10.14.6-security_update_2019-005 | |
Apple iOS and macOS | =10.14.6-security_update_2019-006 | |
Apple iOS and macOS | =10.14.6-security_update_2019-007 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-003 | |
Apple iOS and macOS | =10.14.6-supplemental_update | |
Apple iOS and macOS | =10.14.6-supplemental_update_2 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-11758 is a vulnerability in the ImageIO library that allows attackers to execute arbitrary code or cause a denial of service.
CVE-2020-11758 affects macOS Catalina 10.15.6, macOS Mojave, macOS High Sierra, iOS up to 13.6, iPadOS up to 13.6, watchOS up to 6.2.8, iCloud for Windows up to 7.20, tvOS up to 13.4.8, and iTunes for Windows up to 12.10.8.
To mitigate CVE-2020-11758, update your software to the recommended versions provided by Apple.
Yes, you can find more information about CVE-2020-11758 in the following references: [Reference 1](https://support.apple.com/en-us/HT211289), [Reference 2](https://support.apple.com/en-us/HT211295), [Reference 3](https://support.apple.com/en-us/HT211288).
The Common Weakness Enumeration (CWE) ID for CVE-2020-11758 is 119.