CVE-2020-15306: Buffer Overflow
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15306?
CVE-2020-15306 is a vulnerability discovered in OpenEXR before v2.5.2 that could cause a heap buffer overflow.
What is the severity of CVE-2020-15306?
The severity of CVE-2020-15306 is medium with a severity value of 5.5.
Which software versions are affected by CVE-2020-15306?
OpenEXR versions up to and excluding v2.5.2 are affected by CVE-2020-15306.
How can I fix CVE-2020-15306?
To fix CVE-2020-15306, update your OpenEXR installation to version 2.5.2 or higher.
Where can I find more information about CVE-2020-15306?
You can find more information about CVE-2020-15306 at the following links: [CVE-2020-15306](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15306), [OpenEXR Changelog](https://github.com/AcademySoftwareFoundation/openexr/blob/master/CHANGES.md), [OpenEXR Security Advisory](https://github.com/AcademySoftwareFoundation/openexr/blob/master/SECURITY.md).