CVE-2020-13494 is a heap overflow vulnerability in Pixar OpenUSD 20.05, specifically affecting the parsing of compressed string tokens in binary USD files, impacting Apple macOS and Pixar OpenUSD. An attacker can trigger this by providing a specially crafted, malformed file, leading to out-of-bounds memory access and potential information disclosure. With a CVSS score of 5.5 (Medium), it requires user interaction (UI:R) and local access (AV:L), but could bypass mitigations for further exploitation. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20.05CPE matchmatch criteria | cpe:2.3:a:pixar:openusd:20.05:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.