CVE-2020-11764
Summary
| CVE | CVE-2020-11764 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-14 23:15:00 UTC |
| Updated | 2023-11-07 03:15:00 UTC |
| Description | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-4755-1 openexr |
DEBIAN |
www.debian.org |
|
| About the security content of watchOS 6.2.8 - Apple Support |
CONFIRM |
support.apple.com |
|
| OpenEXR: Multiple vulnerabilities (GLSA 202107-27) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Release v2.4.1 · AcademySoftwareFoundation/openexr · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| tvOS 13.4.8'in güvenlik içeriği hakkında - Apple Destek |
CONFIRM |
support.apple.com |
|
| About the security content of iCloud for Windows 7.20 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of iCloud for Windows 11.3 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of iTunes 12.10.8 for Windows - Apple Support |
CONFIRM |
support.apple.com |
|
| [security-announce] openSUSE-SU-2020:0682-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| USN-4339-1: OpenEXR vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| About the security content of iOS 13.6 and iPadOS 13.6 - Apple Support |
CONFIRM |
support.apple.com |
|
| [SECURITY] [DLA 2358-1] openexr security update |
MLIST |
lists.debian.org |
|
| About the security content of macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra - Apple Support |
CONFIRM |
support.apple.com |
|
| openexr/CHANGES.md at master · AcademySoftwareFoundation/openexr · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| [SECURITY] Fedora 32 Update: mingw-OpenEXR-2.4.1-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: mingw-OpenEXR-2.4.1-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 1987 -
project-zero -
Project Zero -
Monorail |
MISC |
bugs.chromium.org |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377240 Alibaba Cloud Linux Security Update for openexr (ALINUX2-SA-2020:0156)
- 502132 Alpine Linux Security Update for openexr
- 670254 EulerOS Security Update for OpenEXR (EulerOS-SA-2021-1822)
- 672178 EulerOS Security Update for openexr (EulerOS-SA-2022-2475)
- 710048 Gentoo Linux OpenEXR Multiple Vulnerabilities (GLSA 202107-27)