CVE-2020-11759
14.04.2020, 23:15
An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.Enginsight
Vendor | Product | Version |
---|---|---|
openexr | openexr | 𝑥 < 2.4.1 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 19.10 |
canonical | ubuntu_linux | 20.04 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
apple | icloud | 𝑥 < 7.20 |
apple | icloud | 10.0 ≤ 𝑥 < 11.3 |
apple | itunes | 𝑥 < 12.10.8 |
apple | ipados | 𝑥 < 13.6 |
apple | iphone_os | 𝑥 < 13.6 |
apple | mac_os_x | 10.13.0 ≤ 𝑥 < 10.13.6 |
apple | mac_os_x | 10.14.0 ≤ 𝑥 < 10.14.6 |
apple | mac_os_x | 10.15 ≤ 𝑥 < 10.15.6 |
apple | mac_os_x | 10.13.6 |
apple | mac_os_x | 10.13.6:security_update_2018-002 |
apple | mac_os_x | 10.13.6:security_update_2018-003 |
apple | mac_os_x | 10.13.6:security_update_2019-001 |
apple | mac_os_x | 10.13.6:security_update_2019-002 |
apple | mac_os_x | 10.13.6:security_update_2019-003 |
apple | mac_os_x | 10.13.6:security_update_2019-004 |
apple | mac_os_x | 10.13.6:security_update_2019-005 |
apple | mac_os_x | 10.13.6:security_update_2019-006 |
apple | mac_os_x | 10.13.6:security_update_2019-007 |
apple | mac_os_x | 10.13.6:security_update_2020-001 |
apple | mac_os_x | 10.13.6:security_update_2020-002 |
apple | mac_os_x | 10.13.6:security_update_2020-003 |
apple | mac_os_x | 10.14.6 |
apple | mac_os_x | 10.14.6:security_update_2019-001 |
apple | mac_os_x | 10.14.6:security_update_2019-002 |
apple | mac_os_x | 10.14.6:security_update_2019-004 |
apple | mac_os_x | 10.14.6:security_update_2019-005 |
apple | mac_os_x | 10.14.6:security_update_2019-006 |
apple | mac_os_x | 10.14.6:security_update_2019-007 |
apple | mac_os_x | 10.14.6:security_update_2020-001 |
apple | mac_os_x | 10.14.6:security_update_2020-002 |
apple | mac_os_x | 10.14.6:security_update_2020-003 |
apple | tvos | 𝑥 < 13.4.8 |
apple | watchos | 𝑥 < 6.2.8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References