An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access in TfToken Type Index. This vulnerability could be used to bypass mitigations and aid further exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-5743 An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access in TfToken Type Index. This vulnerability could be used to bypass mitigations and aid further exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-08-04T12:18:18.337Z

Reserved: 2020-05-26T00:00:00

Link: CVE-2020-13496

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-02T18:15:12.353

Modified: 2024-11-21T05:01:22.707

Link: CVE-2020-13496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.