### [CVE-2018-20652](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20652) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception. ### POC #### Reference - https://github.com/syoyo/tinyexr/issues/104 - https://github.com/syoyo/tinyexr/issues/104 #### Github - https://github.com/fuzz-evaluator/MemLock-Fuzz-eval - https://github.com/wcventure/MemLock-Fuzz