An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A specially crafted malformed file can trigger an out of bounds memory modification which can result in remote code execution. To trigger this vulnerability, victim needs to access an attacker-provided malformed file.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "11.1"
}
],
"source": "CPE_RANGE",
"vendor_product": "apple:macos"
}
]
}