VDB
GCVE-VVD-MAGEIA-2020-189
GCVE-VVD-MAGEIA-2020-189
Advisory Published
The updated packages fix security vulnerabilities:
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read in ImfOptimizedPixelReading.h. (CVE-2020-11758)
An issue was discovered in OpenEXR before 2.4.1. Because of integer
overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and
readSampleCountForLineBlock, an attacker can write to an out-of-bounds
pointer. (CVE-2020-11759)
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read during RLE uncompression in rleUncompress in ImfRle.cpp.
(CVE-2020-11760)
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read during Huffman uncompression, as demonstrated by FastHufDecoder::refill
in ImfFastHuf.cpp. (CVE-2020-11761)
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when
handling the UNKNOWN compression case. (CVE-2020-11762)
An issue was discovered in OpenEXR before 2.4.1. There is an std::vector
out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
(CVE-2020-11763)
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds
write in copyIntoFrameBuffer in ImfMisc.cpp. (CVE-2020-11764)
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error
in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier,
leading to an out-of-bounds read. (CVE-2020-11765)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | openexr | 0 (affected), 2.3.0-2.2.mga7 (unaffected), 0 (affected), 2.3.0-2.2.mga7 (unaffected) | — |
| Mageia | kodi | 0 (affected), 18.8-1.mga7 (unaffected) | — |
Aliases
Transitive aliases
GSD-2020-11759BDU:2021-03603VAR-202004-0470GSD-2020-11762CNVD-2020-24155VVD-GENTOO-2020-717474BDU:2021-03550CNVD-2021-18054GHSA-p928-c9c9-qw29GHSA-f8m4-63vc-c2g7GHSA-p94m-h527-55cxEUVD-2020-8548CNVD-2022-19856BDU:2021-03609CNVD-2020-24152CNVD-2020-24158VAR-202004-0472CNVD-2022-19858VAR-202004-0475BDU:2021-03551GHSA-9rrf-xw5h-f29cGSD-2020-16587GSD-2020-16589VVD-MAGEIA-2021-15GSD-2020-15305CNVD-2021-18053EUVD-2020-4101GHSA-hjj6-gq2r-v84qCNVD-2022-19857GSD-2020-11758GHSA-46h8-9xpr-rf6wEUVD-2020-4102EUVD-2020-7302EUVD-2020-8550GHSA-fgpm-pph8-mf9rBDU:2021-03608GSD-2020-15306CVE-2020-16588EUVD-2020-7301BDU:2021-03614CNVD-2021-18055BDU:2021-03731GHSA-r5w4-rhqv-q6mvGSD-2020-15304GHSA-5wr6-26jx-jwqgBDU:2021-05191GSD-2020-11765CVE-2020-16589BDU:2021-03732CVE-2020-15305VAR-202004-0469GSD-2020-11760GHSA-72qj-6vqg-mprgCVE-2020-15306CVE-2020-16587EUVD-2020-4100VAR-202004-0468EUVD-2020-4107BDU:2021-03610EUVD-2020-4104EUVD-2020-7303CNVD-2020-24151GHSA-rhrf-xrq9-3h4hCNVD-2020-24153CVE-2020-15304GSD-2020-16588EUVD-2020-8549
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.