Vulnerability Name:

CVE-2020-11765 (CCN-179908)

Assigned:2019-12-12
Published:2019-12-12
Updated:2023-01-09
Summary:
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
5.0 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L)
4.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
3.2 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-11765

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: CCN
Type: Google Security Research Issue 1987
OpenEXR: Multiple Memory Safety Issues

Source: cve@mitre.org
Type: Exploit, Third Party Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
openexr-imfxdr-cve202011765-dos(179908)

Source: cve@mitre.org
Type: Release Notes, Third Party Advisory
cve@mitre.org

Source: CCN
Type: OpenEXR GIT Repository
2.4.1

Source: cve@mitre.org
Type: Release Notes, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: CCN
Type: Packet Storm Security [02-20-2020]
OpenEXR Memory Safety Issues

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: CCN
Type: Apple security document HT211289
About the security content of macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:openexr:openexr:2.4.0:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:202011765
    V
    CVE-2020-11765
    2023-06-22
    oval:org.opensuse.security:def:7908
    P
    libIlmImf-2_2-23-2.2.1-3.41.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3658
    P
    Security update for mokutil (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:3646
    P
    Security update for webkit2gtk3 (Important) (in QA)
    2022-08-01
    oval:org.opensuse.security:def:3006
    P
    ant-1.9.4-3.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3008
    P
    apache-commons-daemon-1.0.15-6.10 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:2998
    P
    DirectFB-1.7.1-6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3290
    P
    libxslt-tools-1.1.28-17.6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94920
    P
    libIlmImf-2_2-23-2.2.1-3.41.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2959
    P
    kdump-1.0.2+git10.g26f0b96-150400.1.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2939
    P
    graphite2-devel-1.3.11-2.12 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2921
    P
    flac-devel-1.3.2-3.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2968
    P
    libFS-devel-1.0.7-1.22 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2953
    P
    ipsec-tools-0.8.2-5.35 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2927
    P
    gd-devel-2.2.5-11.3.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2992
    P
    libXxf86vm-devel-1.1.4-1.23 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2917
    P
    expat-2.4.4-150400.2.24 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1675
    P
    Security update for grub2 (Important)
    2022-06-13
    oval:org.opensuse.security:def:94031
    P
    (Moderate)
    2022-06-02
    oval:org.opensuse.security:def:100744
    P
    (Critical)
    2022-02-08
    oval:org.opensuse.security:def:1560
    P
    Security update for the Linux Kernel (Important)
    2022-01-25
    oval:org.opensuse.security:def:1204
    P
    Security update for python-numpy (Moderate)
    2022-01-20
    oval:org.opensuse.security:def:68544
    P
    Security update for p11-kit (Important)
    2021-12-22
    oval:org.opensuse.security:def:64635
    P
    Security update for python-pip (Moderate)
    2021-12-13
    oval:org.opensuse.security:def:69962
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:64805
    P
    Security update for python-Pygments (Important)
    2021-12-01
    oval:org.opensuse.security:def:74747
    P
    Security update for go1.16 (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:2132
    P
    libvirglrenderer0-0.6.0-2.30 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2123
    P
    libecpg6-10.6-6.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2149
    P
    skopeo-0.1.32-4.5.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2141
    P
    postgresql-contrib-10-6.8 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2127
    P
    librelp-devel-1.2.15-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2121
    P
    libapr-util1-dbd-mysql-1.6.1-4.3.8 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2143
    P
    qemu-3.1.0-7.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63381
    P
    sysstat-isag-12.0.2-3.27.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:71781
    P
    c-ares-devel-1.17.0-3.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101170
    P
    libIlmImf-2_2-23-2.2.1-3.24.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62764
    P
    libIlmImf-2_2-23-2.2.1-3.24.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72483
    P
    libIlmImf-2_2-23-2.2.1-3.24.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71897
    P
    libical3-3.0.6-4.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64533
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:48780
    P
    java-1_7_0-openjdk-plugin-1.6.1-2.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48638
    P
    unixODBC-2.3.4-6.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48639
    P
    unzip-6.00-32.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62878
    P
    subversion-bash-completion-1.10.0-1.24 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48655
    P
    xorg-x11-server-7.6_1.18.3-57.34 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64693
    P
    Security update for hivex (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:65558
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:52029
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:68802
    P
    Security update for the Linux Kernel (Important)
    2021-02-10
    oval:org.opensuse.security:def:49453
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:66711
    P
    Security update for jetty-minimal (Moderate)
    2020-12-22
    oval:org.opensuse.security:def:73402
    P
    Security update for openssh (Moderate)
    2020-12-17
    oval:org.opensuse.security:def:72258
    P
    libXi6-32bit-1.7.9-1.23 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2171
    P
    dpdk-19.11.1-1.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62885
    P
    ant-antlr-1.9.10-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63584
    P
    libgadu-devel-1.12.2-1.44 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62649
    P
    libIlmImf-2_2-23-2.2.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116968
    P
    libIlmImf-2_2-23-2.2.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63088
    P
    reiserfs-kmp-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72368
    P
    libIlmImf-2_2-23-2.2.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72142
    P
    libQt5OpenGLExtensions-devel-static-5.9.4-6.48 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107410
    P
    libIlmImf-2_2-23-2.2.1-3.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48978
    P
    colord-1.3.3-12.13 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2166
    P
    apache2-mod_wsgi-python3-4.5.18-2.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2176
    P
    grub2-x86_64-xen-2.04-7.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62882
    P
    FastCGI-2.4.0-2.23 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2178
    P
    ipmitool-bmc-snmp-proxy-1.8.18+git20200204.7ccea28-1.22 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62910
    P
    ocaml-4.05.0-4.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2816
    P
    Security update for djvulibre (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2826
    P
    Security update for openexr (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:65468
    P
    Security update for openssl-1_0_0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50186
    P
    gnome-online-accounts on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68905
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49819
    P
    bouncycastle on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49645
    P
    libIlmImf-2_2-23 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64426
    P
    pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49598
    P
    rtkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51199
    P
    Security update for openexr (Low)
    2020-12-01
    oval:org.opensuse.security:def:49931
    P
    clamsap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50680
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49754
    P
    perl-Config-IniFiles on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66619
    P
    rpm-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64289
    P
    ldns-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49213
    P
    libpcre1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49923
    P
    python2-paramiko on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70067
    P
    libIlmImf-2_2-23 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50649
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51261
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49580
    P
    libthai-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74880
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50424
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:49434
    P
    libexif-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63731
    P
    Security update for expat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50584
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:49687
    P
    libpango-1_0-0-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68441
    P
    Security update for libsolv, libzypp, zypper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49435
    P
    libexiv2-26 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50029
    P
    rarpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50753
    P
    Security update for libvpx (Important)
    2020-12-01
    oval:org.opensuse.security:def:52091
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64425
    P
    p7zip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65107
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49367
    P
    yubikey-manager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73284
    P
    perl-Mail-SpamAssassin on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49785
    P
    guile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50514
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:49591
    P
    perl-MIME-Charset on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63960
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:49119
    P
    hplip-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49850
    P
    ocaml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65197
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:110542
    P
    Security update for openexr (Moderate)
    2020-05-22
    oval:org.opensuse.security:def:90924
    P
    Security update for openexr (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:104579
    P
    Security update for openexr (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:97510
    P
    Security update for openexr (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:90545
    P
    Security update for openexr (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:97889
    P
    Security update for openexr (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:75285
    P
    Security update for openexr (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:104200
    P
    Security update for openexr (Moderate)
    2020-05-18
    BACK
    openexr openexr 2.4.0 -