CVE-2020-15304: Fedoraproject Fedora
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
Affected products
- Fedoraproject Fedora: version 31 only; version 32 only
- Openexr Openexr: before 2.5.2 (fixed in 2.5.2)
- Opensuse Leap: version 15.1 only; version 15.2 only
Published 2020-06-26. Last modified 2026-06-17.