CVE-2020-15305: Use After Free
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15305?
CVE-2020-15305 is a vulnerability in OpenEXR before 2.5.2 that could result in a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile().
How severe is CVE-2020-15305?
CVE-2020-15305 has a severity rating of 5.5 (medium).
What software is affected by CVE-2020-15305?
OpenEXR versions 2.2.0-11.1ubuntu1.3, 2.2.1-4.1ubuntu1.2, 2.3.0-6ubuntu0.2, 2.2.0-10ubuntu2.3, and 2.5.2 are affected. Also affected are Fedora 31, Fedora 32, openSUSE Leap 15.1, openSUSE Leap 15.2, Debian Debian Linux 9.0, Debian Debian Linux 10.0, Canonical Ubuntu Linux 16.04, Canonical Ubuntu Linux 18.04, Canonical Ubuntu Linux 19.10, and Canonical Ubuntu Linux 20.04.
How do I fix CVE-2020-15305?
Update OpenEXR to version 2.5.2 or later to fix CVE-2020-15305.
Where can I find more information about CVE-2020-15305?
More information about CVE-2020-15305 can be found on the MITRE CVE website: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15305