Heap-based buffer overflow in OpenEXR - CVE-2020-16587
Published: March 3, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp. A remote attacker can use a specially crafted EXR file, trigger heap-based buffer overflow and cause a denial of service condition on the target system.
Affected software
Ubuntu
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libopenexr24 (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2020-16587
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4, 2.3.0-6ubuntu0.3
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.3
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11