A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. This instance exists in the USDC file format FIELDS section decompression heap overflow.
References
Link | Resource |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1094 | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2020/Nov/20 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2020-11-13 15:15
Updated : 2022-05-13 20:57
NVD link : CVE-2020-6147
Mitre link : CVE-2020-6147
JSON object : View
Products Affected
pixar
- openusd
apple
- ipados
- iphone_os
CWE
CWE-787
Out-of-bounds Write