CVE-2020-11761: Buffer Overflow
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
Other sources
ImageIO. Multiple issues in openEXR were addressed with improved checks.
Credit
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9884
- CVE-2020-9889
- CVE-2020-9888
- CVE-2020-9890
- CVE-2020-9891
- CVE-2020-9907
- CVE-2020-9883
- CVE-2020-9865
- CVE-2020-9900
- CVE-2020-9980
- CVE-2020-9933
- CVE-2020-9914
- CVE-2020-27933
- CVE-2020-11758
- CVE-2020-11759
- CVE-2020-11760
- CVE-2020-11761
- CVE-2020-11762
- CVE-2020-11763
- CVE-2020-11764
- CVE-2020-11765
- CVE-2020-9871
- CVE-2020-9872
- CVE-2020-9874
- CVE-2020-9879
- CVE-2020-9936
- CVE-2020-9937
- CVE-2020-9919
- CVE-2020-9876
- CVE-2020-9873
- CVE-2020-9938
- CVE-2020-9984
- CVE-2020-9877
- CVE-2020-9875
- CVE-2019-14899
- CVE-2020-9909
- CVE-2020-9904
- CVE-2020-9863
- CVE-2020-9892
- CVE-2020-9902
- CVE-2020-9905
- CVE-2020-9926
- CVE-2020-9880
- CVE-2020-9878
- CVE-2020-9940
- CVE-2020-9868
- CVE-2020-9901
- CVE-2020-9894
- CVE-2020-9915
- CVE-2020-9925
- CVE-2020-9893
- CVE-2020-9895
- CVE-2020-9910
- CVE-2020-9916
- CVE-2020-9862
- CVE-2020-6514
- CVE-2020-9918
- CVE-2020-9927
- CVE-2020-9928
- CVE-2020-9929
- CVE-2020-9870
- CVE-2020-9866
- CVE-2020-9869
- CVE-2020-9949
- CVE-2020-9934
- CVE-2020-9799
- CVE-2020-9913
- CVE-2020-9887
- CVE-2020-9908
- CVE-2020-9990
- CVE-2020-9921
- CVE-2020-9924
- CVE-2020-9997
- CVE-2020-9994
- CVE-2020-9935
- CVE-2019-19906
- CVE-2020-9920
- CVE-2020-9922
- CVE-2020-9885
- CVE-2020-9881
- CVE-2020-9882
- CVE-2020-9985
- CVE-2020-12243
- CVE-2020-10878
- CVE-2020-12723
- CVE-2014-9512
- CVE-2020-9930
- CVE-2020-9939
- CVE-2020-9864
- CVE-2020-9854
- CVE-2019-20807
- CVE-2020-9898
- CVE-2020-9899
- CVE-2020-9906
- CVE-2020-9923
- CVE-2020-9931
- CVE-2020-9903
- CVE-2020-9911
- CVE-2020-9917
Frequently Asked Questions
What is CVE-2020-11761?
CVE-2020-11761 is a vulnerability in ImageIO that was addressed with improved checks in openEXR.
How does CVE-2020-11761 affect Apple macOS Catalina?
Apple macOS Catalina with a version up to, but not including, 10.15.6 is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple Mojave?
Apple Mojave is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple High Sierra?
Apple High Sierra is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple iOS?
Apple iOS with a version up to, but not including, 13.6 is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple iPadOS?
Apple iPadOS with a version up to, but not including, 13.6 is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple watchOS?
Apple watchOS with a version up to, but not including, 6.2.8 is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple iCloud for Windows?
Apple iCloud for Windows with a version up to, but not including, 7.20 is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple tvOS?
Apple tvOS with a version up to, but not including, 13.4.8 is affected by CVE-2020-11761.
How does CVE-2020-11761 affect Apple iTunes for Windows?
Apple iTunes for Windows with a version up to, but not including, 12.10.8 is affected by CVE-2020-11761.
What is the Common Weakness Enumeration (CWE) for CVE-2020-11761?
The Common Weakness Enumeration (CWE) for CVE-2020-11761 is CWE-119.
Where can I find more information about CVE-2020-11761?
You can find more information about CVE-2020-11761 on Apple's support page: [https://support.apple.com/en-us/HT211289](https://support.apple.com/en-us/HT211289), [https://support.apple.com/en-us/HT211295](https://support.apple.com/en-us/HT211295), [https://support.apple.com/en-us/HT211288](https://support.apple.com/en-us/HT211288).