First published: Tue Apr 14 2020(Updated: )
An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <11.3 | 11.3 |
Apple iTunes for Windows | <12.10.8 | 12.10.8 |
Apple iCloud for Windows | <7.20 | 7.20 |
Apple macOS Catalina | <10.15.6 | 10.15.6 |
Apple Mojave | ||
Apple High Sierra | ||
Apple watchOS | <6.2.8 | 6.2.8 |
Apple tvOS | <13.4.8 | 13.4.8 |
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
debian/openexr | 2.5.4-2+deb11u1 3.1.5-5 3.1.5-5.1 | |
OpenEXR | <2.4.1 | |
Fedoraproject Fedora | =32 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Apple Icloud Windows | <7.20 | |
Apple Icloud Windows | >=10.0<11.3 | |
Apple Itunes Windows | <12.10.8 | |
Apple iPadOS | <13.6 | |
Apple iPhone OS | <13.6 | |
Apple Mac OS X | >=10.13.0<10.13.6 | |
Apple Mac OS X | >=10.14.0<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.6 | |
Apple Mac OS X | =10.13.6 | |
Apple Mac OS X | =10.13.6-security_update_2018-002 | |
Apple Mac OS X | =10.13.6-security_update_2018-003 | |
Apple Mac OS X | =10.13.6-security_update_2019-001 | |
Apple Mac OS X | =10.13.6-security_update_2019-002 | |
Apple Mac OS X | =10.13.6-security_update_2019-003 | |
Apple Mac OS X | =10.13.6-security_update_2019-004 | |
Apple Mac OS X | =10.13.6-security_update_2019-005 | |
Apple Mac OS X | =10.13.6-security_update_2019-006 | |
Apple Mac OS X | =10.13.6-security_update_2019-007 | |
Apple Mac OS X | =10.13.6-security_update_2020-001 | |
Apple Mac OS X | =10.13.6-security_update_2020-002 | |
Apple Mac OS X | =10.13.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2019-004 | |
Apple Mac OS X | =10.14.6-security_update_2019-005 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple tvOS | <13.4.8 | |
Apple watchOS | <6.2.8 |
https://github.com/AcademySoftwareFoundation/openexr/commit/b9997d0c045fa01af3d2e46e1a74b07cc4519446
https://github.com/AcademySoftwareFoundation/openexr/commit/acad98d6d3e787f36012a3737c23c42c7f43a00f
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2020-11759.
The affected software includes macOS Catalina, Mojave, High Sierra, iOS, iPadOS, watchOS, iCloud for Windows, tvOS, and iTunes for Windows.
The severity of CVE-2020-11759 has not been specified.
To fix CVE-2020-11759, update to the latest version of the affected software. Please refer to the official Apple support links for specific remediation steps.
You can find more information about CVE-2020-11759 on the official Apple support website. Please refer to the provided reference links.