Out-of-bounds read in OpenEXR - CVE-2020-11761

 

Out-of-bounds read in OpenEXR - CVE-2020-11761

Published: April 15, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34465
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11761
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.


Affected software

OpenEXR
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Opensuse
openEuler
Fedora
openexr (Debian package)
OpenEXR (Red Hat package)
OpenEXR
OpenEXR-debuginfo
OpenEXR-devel
OpenEXR-libs
OpenEXR-debugsource
mingw-openexr
mingw-ilmbase
Data Computing Appliance (DCA)

How to mitigate CVE-2020-11761

Install update from vendor's website.

OpenEXR - update to 2.4.1
openexr (Debian package) - update to 2.2.1-4.1+deb10u1
OpenEXR (Red Hat package) - update to 1.7.1-8.el7
OpenEXR - update to 2.2.0-22
OpenEXR-debuginfo - update to 2.2.0-22
OpenEXR-devel - update to 2.2.0-22
OpenEXR-libs - update to 2.2.0-22
OpenEXR-debugsource - update to 2.2.0-22
mingw-openexr - update to 2.4.1-1.fc32
mingw-ilmbase - update to 2.4.1-1.fc32
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins