CVE-2020-6156: High severity pixar openusd vulnerability
Published Nov 13, 2020
·Updated
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file in an instance USDC file format path element token index.
Affected Software
1 affected component
Pixar OpenUSD=20.05
Event History
Nov 13, 2020
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability identifier for this vulnerability?
The vulnerability identifier for this vulnerability is CVE-2020-6156.
2
What is the affected software?
The affected software is Pixar OpenUSD version 20.05.
3
How severe is CVE-2020-6156?
CVE-2020-6156 has a severity rating of 7.8 (high).
4
What is the cause of this vulnerability?
This vulnerability is caused by a heap overflow when parsing compressed sections in binary USD files.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by opening an attacker-provided malformed file in an instance USDC file format path element token index.