First published: Wed Dec 09 2020(Updated: )
A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openexr Openexr | =2.3.0 | |
Debian Debian Linux | =10.0 |
https://github.com/AcademySoftwareFoundation/openexr/commit/74504503cff86e986bac441213c403b0ba28d58f
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16588 is a Null Pointer Deference issue in Academy Software Foundation OpenEXR 2.3.0 that can cause a denial of service via a crafted EXR file.
CVE-2020-16588 has a severity rating of 5.5 (medium).
Academy Software Foundation OpenEXR 2.3.0 and Debian Debian Linux 10.0 are affected by CVE-2020-16588.
CVE-2020-16588 can be exploited by using a crafted EXR file.
To fix CVE-2020-16588, you should update to the latest version of Academy Software Foundation OpenEXR or apply the necessary patches.