tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
References
Link | Resource |
---|---|
https://github.com/syoyo/tinyexr/commit/a685e3332f61cd4e59324bf3f669d36973d64270 | Patch Third Party Advisory |
https://github.com/syoyo/tinyexr/issues/124 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-07-21 11:15
Updated : 2021-07-30 17:27
NVD link : CVE-2020-19490
Mitre link : CVE-2020-19490
JSON object : View
CWE
CWE-190
Integer Overflow or Wraparound
Products Affected
tinyexr_project
- tinyexr