First published: Fri Jun 26 2020(Updated: )
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openexr Openexr | <2.5.2 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15304 is a vulnerability in OpenEXR before 2.5.2 that could result in invalid memory access.
The severity of CVE-2020-15304 is medium, with a severity score of 5.5.
OpenEXR versions up to 2.5.2 are affected, as well as Fedora 31, Fedora 32, openSUSE Leap 15.1, and openSUSE Leap 15.2.
An attacker can exploit the CVE-2020-15304 vulnerability by providing an invalid tiled input file, leading to a NULL pointer dereference and potential invalid memory access.
Yes, you can find more information about CVE-2020-15304 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00025.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00025.html), [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00048.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00048.html), and [https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md](https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md).