A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp that can cause a denial of service via a crafted EXR file.
[
{
"signature_version": "v1",
"source": "https://github.com/academysoftwarefoundation/openexr/commit/8b5370c688a7362673c3a5256d93695617a4cd9a",
"deprecated": false,
"id": "CVE-2020-16587-2ec0a54b",
"signature_type": "Function",
"digest": {
"length": 4663.0,
"function_hash": "143967905294990520278655521811818684950"
},
"target": {
"function": "MultiPartInputFile::Data::chunkOffsetReconstruction",
"file": "OpenEXR/IlmImf/ImfMultiPartInputFile.cpp"
}
},
{
"signature_version": "v1",
"source": "https://github.com/academysoftwarefoundation/openexr/commit/8b5370c688a7362673c3a5256d93695617a4cd9a",
"deprecated": false,
"id": "CVE-2020-16587-eec94311",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"134578106560149560542039773809397150419",
"64017740078096563740224162377099776518",
"176058261214050518461075301377133407243",
"101883906199073792821308977749009224060"
]
},
"target": {
"file": "OpenEXR/IlmImf/ImfMultiPartInputFile.cpp"
}
}
]