A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp that can cause a denial of service via a crafted EXR file.
{ "vanir_signatures": [ { "id": "CVE-2020-16587-2ec0a54b", "signature_type": "Function", "target": { "file": "OpenEXR/IlmImf/ImfMultiPartInputFile.cpp", "function": "MultiPartInputFile::Data::chunkOffsetReconstruction" }, "signature_version": "v1", "digest": { "length": 4663.0, "function_hash": "143967905294990520278655521811818684950" }, "deprecated": false, "source": "https://github.com/academysoftwarefoundation/openexr/commit/8b5370c688a7362673c3a5256d93695617a4cd9a" }, { "id": "CVE-2020-16587-eec94311", "signature_type": "Line", "target": { "file": "OpenEXR/IlmImf/ImfMultiPartInputFile.cpp" }, "signature_version": "v1", "digest": { "line_hashes": [ "134578106560149560542039773809397150419", "64017740078096563740224162377099776518", "176058261214050518461075301377133407243", "101883906199073792821308977749009224060" ], "threshold": 0.9 }, "deprecated": false, "source": "https://github.com/academysoftwarefoundation/openexr/commit/8b5370c688a7362673c3a5256d93695617a4cd9a" } ] }