A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file.
[
{
"id": "CVE-2020-16588-421f3b2d",
"source": "https://github.com/academysoftwarefoundation/openexr/commit/74504503cff86e986bac441213c403b0ba28d58f",
"signature_type": "Function",
"digest": {
"function_hash": "207297880412268657017143986327863672035",
"length": 1268.0
},
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "generatePreview",
"file": "OpenEXR/exrmakepreview/makePreview.cpp"
}
},
{
"id": "CVE-2020-16588-a4735109",
"source": "https://github.com/academysoftwarefoundation/openexr/commit/74504503cff86e986bac441213c403b0ba28d58f",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"70351851170983403964656738862852043407",
"4291375085864810308672790455693151707",
"7238971007744912712487349499263763413",
"334795955205350761214040432761619524737",
"306323290327291876844197157519246707579"
]
},
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "OpenEXR/exrmakepreview/makePreview.cpp"
}
}
]