CVE-2020-15304: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.

Affected products

  • Fedoraproject Fedora: version 31 only; version 32 only
  • Openexr Openexr: before 2.5.2 (fixed in 2.5.2)
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-06-26. Last modified 2026-06-17.