A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specially crafted file can trigger the reuse of a freed memory which can result in further memory corruption and arbitrary code execution. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published: 2020-12-03T16:23:59

Updated: 2024-08-04T12:18:18.315Z

Reserved: 2020-05-26T00:00:00

Link: CVE-2020-13531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-03T17:15:11.943

Modified: 2022-06-07T18:35:51.157

Link: CVE-2020-13531

cve-icon Redhat

No data.