Heap-based buffer overflow in OpenEXR - CVE-2020-16589
Published: March 3, 2021
Vulnerability identifier: #VU51177
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16589
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in writeTileData in ImfTiledOutputFile.cpp. A remote attacker can use a specially crafted EXR file, trigger heap-based buffer overflow and cause a denial of service condition on the target system.
Affected software
OpenEXR
Ubuntu
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libopenexr24 (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
Ubuntu
openexr (Ubuntu package)
libopenexr22 (Ubuntu package)
libopenexr24 (Ubuntu package)
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2020-16589
Install updates from vendor's website.
OpenEXR - update to 2.4.0
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4, 2.3.0-6ubuntu0.3
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.3
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11
openexr (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4, 2.3.0-6ubuntu0.3
libopenexr22 (Ubuntu package) - addressed in versions 2.2.0-10ubuntu2.4, 2.2.0-11.1ubuntu1.4
libopenexr24 (Ubuntu package) - update to 2.3.0-6ubuntu0.3
Isolation Segment - addressed in versions 2.7.30, 2.8.24, 2.9.18, 2.10.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.31, 2.8.25, 2.9.19, 2.10.11