An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access in String Type Index. This vulnerability could be used to bypass mitigations and aid further exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-5744 An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access in String Type Index. This vulnerability could be used to bypass mitigations and aid further exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-08-04T12:18:18.433Z

Reserved: 2020-05-26T00:00:00

Link: CVE-2020-13497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-02T18:15:12.417

Modified: 2024-11-21T05:01:22.830

Link: CVE-2020-13497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.