A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial of service via a crafted EXR file.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "OpenEXR/IlmImf/ImfTiledInputFile.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "187727245820172389255241288024641761673", "64620396527734480438930043191230067910", "135511452004856887655092018138110768581", "205564678437823994680598713941013802548" ], "threshold": 0.9 }, "id": "CVE-2020-16589-01094440", "source": "https://github.com/academysoftwarefoundation/openexr/commit/6bb36714528a9563dd3b92720c5063a1284b86f8" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "OpenEXR/IlmImf/ImfTiledInputFile.cpp", "function": "TiledInputFile::rawTileData" }, "deprecated": false, "digest": { "length": 1079.0, "function_hash": "315788786115343669113423538237101638126" }, "id": "CVE-2020-16589-09795360", "source": "https://github.com/academysoftwarefoundation/openexr/commit/6bb36714528a9563dd3b92720c5063a1284b86f8" } ] }