CVE-2020-13498
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access which could lead to information disclosure. This vulnerability could be used to bypass mitigations and aid further exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Existe una vulnerabilidad explotable en la forma en que Pixar OpenUSD 20.05 maneja el análisis de ciertos tipos codificados. Un archivo malformado especialmente diseñado puede desencadenar un acceso arbitrario a la memoria fuera de los límites que podría conducir a la divulgación de información. Esta vulnerabilidad podría ser utilizada para eludir las mitigaciones y ayudar a una mayor explotación. Para activar esta vulnerabilidad, la víctima necesita acceder a un archivo malformado proporcionado por el atacante
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-26 CVE Reserved
- 2020-12-02 CVE Published
- 2024-03-17 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1105 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pixar Search vendor "Pixar" | Openusd Search vendor "Pixar" for product "Openusd" | 20.05 Search vendor "Pixar" for product "Openusd" and version "20.05" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|