CVE-2020-13531

Source
https://cve.org/CVERecord?id=CVE-2020-13531
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13531.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13531
Published
2020-12-03T17:15:11Z
Modified
2026-08-27T08:40:33Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specially crafted file can trigger the reuse of a freed memory which can result in further memory corruption and arbitrary code execution. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

References

Affected packages

Git / github.com/PixarAnimationStudios/OpenUSD

Affected ranges

Type
GIT
Repo
https://github.com/PixarAnimationStudios/OpenUSD
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:pixar:openusd:20.08:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "20.08"
        },
        {
            "last_affected": "20.08"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

20.*
20.08
v20.*
v20.08

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13531.json"