ZeroHour

CVE-2020-11762

PoC
CVSS 3.1
5.5 medium
EPSS
2%p77
Published
()
Modified
Description

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.

Vendors
openexrfedoraprojectcanonicalopensusedebianapple
Products
openexr, fedora, ubuntu linux, leap, debian linux, icloud, itunes, ipados, iphone os, mac os x, tvos, watchos
Weakness
CWE-125, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.