CVE-2020-15304: Null Pointer Dereference
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15304?
CVE-2020-15304 is a vulnerability in OpenEXR before 2.5.2 that could result in invalid memory access.
What is the severity of CVE-2020-15304?
The severity of CVE-2020-15304 is medium, with a severity score of 5.5.
Which software versions are affected by CVE-2020-15304?
OpenEXR versions up to 2.5.2 are affected, as well as Fedora 31, Fedora 32, openSUSE Leap 15.1, and openSUSE Leap 15.2.
How can the CVE-2020-15304 vulnerability be exploited?
An attacker can exploit the CVE-2020-15304 vulnerability by providing an invalid tiled input file, leading to a NULL pointer dereference and potential invalid memory access.
Are there any references available for CVE-2020-15304?
Yes, you can find more information about CVE-2020-15304 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00025.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00025.html), [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00048.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00048.html), and [https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md](https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md).