First published: Wed Dec 02 2020(Updated: )
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jumps are processed. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pixar OpenUSD | =20.05 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-13493.
The severity of CVE-2020-13493 is high, with a CVSS score of 7.8.
Pixar OpenUSD 20.05 is affected by CVE-2020-13493.
CVE-2020-13493 occurs due to a heap overflow vulnerability when parsing compressed sections in binary USD files.
No, Apple macOS is not vulnerable to CVE-2020-13493.