An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
2020-12-03T18:15:10.690
2024-11-21T05:01:25.503
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pixar | openusd | 20.05 | Yes |
Operating System | apple | mac_os_x | < 10.14.6 | Yes |
Operating System | apple | mac_os_x | < 10.15.7 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.14.6 | Yes |
Operating System | apple | mac_os_x | 10.15.7 | Yes |
Operating System | apple | macos | < 11.1 | Yes |