Heap-based buffer overflow in OpenEXR - CVE-2020-16587

 

Heap-based buffer overflow in OpenEXR - CVE-2020-16587

Published: March 3, 2021


Vulnerability identifier: #VU51176
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16587
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp. A remote attacker can use a specially crafted EXR file, trigger heap-based buffer overflow and cause a denial of service condition on the target system.


Affected software

OpenEXR
Ubuntu
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libopenexr24 (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs

How to mitigate CVE-2020-16587

Install updates from vendor's website.

OpenEXR - update to 2.4.0
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4, 2.3.0-6ubuntu0.3
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.3
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11

External References

Related Security Bulletins