First published: Fri Jun 26 2020(Updated: )
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openexr Openexr | <2.5.2 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
debian/openexr | 2.5.4-2+deb11u1 3.1.5-5 3.1.5-5.1 | |
ubuntu/openexr | <2.2.0-11.1ubuntu1.3 | 2.2.0-11.1ubuntu1.3 |
ubuntu/openexr | <2.2.1-4.1ubuntu1.2 | 2.2.1-4.1ubuntu1.2 |
ubuntu/openexr | <2.3.0-6ubuntu0.2 | 2.3.0-6ubuntu0.2 |
ubuntu/openexr | <2.2.0-10ubuntu2.3 | 2.2.0-10ubuntu2.3 |
https://github.com/AcademySoftwareFoundation/openexr/commit/3d03979dc101612e806cdf0b011475d9fa685a73
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15305 is a vulnerability in OpenEXR before 2.5.2 that could result in a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile().
CVE-2020-15305 has a severity rating of 5.5 (medium).
OpenEXR versions 2.2.0-11.1ubuntu1.3, 2.2.1-4.1ubuntu1.2, 2.3.0-6ubuntu0.2, 2.2.0-10ubuntu2.3, and 2.5.2 are affected. Also affected are Fedora 31, Fedora 32, openSUSE Leap 15.1, openSUSE Leap 15.2, Debian Debian Linux 9.0, Debian Debian Linux 10.0, Canonical Ubuntu Linux 16.04, Canonical Ubuntu Linux 18.04, Canonical Ubuntu Linux 19.10, and Canonical Ubuntu Linux 20.04.
Update OpenEXR to version 2.5.2 or later to fix CVE-2020-15305.
More information about CVE-2020-15305 can be found on the MITRE CVE website: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15305