CVE-2020-11765

MEDIUM

Openexr < 2.4.1 - Out-of-Bounds Access

Title source: rule
STIX 2.1

Description

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.

Scores

CVSS v3 5.5
EPSS 0.0058
EPSS Percentile 68.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-125 CWE-193
Status published
Products (18)
apple/icloud < 7.20
apple/ipados < 13.6
apple/iphone_os < 13.6
apple/itunes < 12.10.8
apple/mac_os_x 10.13.6 (14 CPE variants)
apple/mac_os_x 10.14.6 (12 CPE variants)
apple/mac_os_x 10.13.0 - 10.13.6
apple/tvos < 13.4.8
apple/watchos < 6.2.8
canonical/ubuntu_linux 16.04
... and 8 more
Published Apr 14, 2020
Tracked Since Feb 18, 2026