First published: Tue Apr 14 2020(Updated: )
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <11.3 | 11.3 |
Apple iTunes for Windows | <12.10.8 | 12.10.8 |
Apple iCloud for Windows | <7.20 | 7.20 |
Apple macOS Catalina | <10.15.6 | 10.15.6 |
Apple Mojave | ||
Apple High Sierra | ||
Apple watchOS | <6.2.8 | 6.2.8 |
Apple tvOS | <13.4.8 | 13.4.8 |
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
debian/openexr | 2.5.4-2+deb11u1 3.1.5-5 3.1.5-5.1 | |
OpenEXR | <2.4.1 | |
Fedoraproject Fedora | =32 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Apple Icloud Windows | <7.20 | |
Apple Icloud Windows | >=10.0<11.3 | |
Apple Itunes Windows | <12.10.8 | |
Apple iPadOS | <13.6 | |
Apple iPhone OS | <13.6 | |
Apple Mac OS X | <10.15.6 | |
Apple Mac OS X | >=10.13.0<10.13.6 | |
Apple Mac OS X | >=10.14.0<10.14.6 | |
Apple Mac OS X | =10.13.6 | |
Apple Mac OS X | =10.13.6-security_update_2018-002 | |
Apple Mac OS X | =10.13.6-security_update_2018-003 | |
Apple Mac OS X | =10.13.6-security_update_2019-001 | |
Apple Mac OS X | =10.13.6-security_update_2019-002 | |
Apple Mac OS X | =10.13.6-security_update_2019-003 | |
Apple Mac OS X | =10.13.6-security_update_2019-004 | |
Apple Mac OS X | =10.13.6-security_update_2019-005 | |
Apple Mac OS X | =10.13.6-security_update_2019-006 | |
Apple Mac OS X | =10.13.6-security_update_2019-007 | |
Apple Mac OS X | =10.13.6-security_update_2020-001 | |
Apple Mac OS X | =10.13.6-security_update_2020-002 | |
Apple Mac OS X | =10.13.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2019-004 | |
Apple Mac OS X | =10.14.6-security_update_2019-005 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple tvOS | <13.4.8 | |
Apple watchOS | <6.2.8 |
https://github.com/AcademySoftwareFoundation/openexr/commit/b1c34c496b62117115b1089b18a44e0031800a09
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-11761 is a vulnerability in ImageIO that was addressed with improved checks in openEXR.
Apple macOS Catalina with a version up to, but not including, 10.15.6 is affected by CVE-2020-11761.
Apple Mojave is affected by CVE-2020-11761.
Apple High Sierra is affected by CVE-2020-11761.
Apple iOS with a version up to, but not including, 13.6 is affected by CVE-2020-11761.
Apple iPadOS with a version up to, but not including, 13.6 is affected by CVE-2020-11761.
Apple watchOS with a version up to, but not including, 6.2.8 is affected by CVE-2020-11761.
Apple iCloud for Windows with a version up to, but not including, 7.20 is affected by CVE-2020-11761.
Apple tvOS with a version up to, but not including, 13.4.8 is affected by CVE-2020-11761.
Apple iTunes for Windows with a version up to, but not including, 12.10.8 is affected by CVE-2020-11761.
The Common Weakness Enumeration (CWE) for CVE-2020-11761 is CWE-119.
You can find more information about CVE-2020-11761 on Apple's support page: [https://support.apple.com/en-us/HT211289](https://support.apple.com/en-us/HT211289), [https://support.apple.com/en-us/HT211295](https://support.apple.com/en-us/HT211295), [https://support.apple.com/en-us/HT211288](https://support.apple.com/en-us/HT211288).