A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. This instance exists in the USDC file format FIELDS section decompression heap overflow.
References
Link | Resource |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1094 | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2020/Nov/20 | Mailing List Third Party Advisory |
Information
Published : 2020-11-13 07:15
Updated : 2022-05-13 13:57
NVD link : CVE-2020-6147
Mitre link : CVE-2020-6147
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
pixar
- openusd
apple
- iphone_os
- ipados