CVE-2020-13495
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the disclosure of sensitive information. This vulnerability could be used to bypass mitigations and aid additional exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided file.
Se presenta una vulnerabilidad explotable en la forma en que Pixar OpenUSD versión 20.05 maneja las compensaciones de archivos en los archivos binarios USD. Un archivo malformado especialmente diseñado puede desencadenar un acceso arbitrario a la memoria fuera de límites que podría conllevar a una divulgación de información confidencial. Esta vulnerabilidad podría usarse para omitir las mitigaciones y ayudar a una explotación adicional. Para desencadenar esta vulnerabilidad, la víctima necesita acceder a un archivo proporcionado por el atacante
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-26 CVE Reserved
- 2022-04-18 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-11-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1104 | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pixar Search vendor "Pixar" | Openusd Search vendor "Pixar" for product "Openusd" | 20.05 Search vendor "Pixar" for product "Openusd" and version "20.05" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.15.3 Search vendor "Apple" for product "Mac Os X" and version "10.15.3" | - |
Safe
|