NULL pointer dereference in OpenEXR - CVE-2020-16588
Published: March 3, 2021
Vulnerability identifier: #VU51175
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16588
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in generatePreview in makePreview.cpp. A remote attacker can use a specially crafted EXR file and perform a denial of service (DoS) attack.
Affected software
OpenEXR
Ubuntu
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libopenexr24 (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
Ubuntu
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libopenexr24 (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2020-16588
Install updates from vendor's website.
OpenEXR - update to 2.4.0
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4, 2.3.0-6ubuntu0.3
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.3
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4, 2.3.0-6ubuntu0.3
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.3
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11