Blog | G5 Cyber Security

Vulnerability Spotlight: Walt Disney Per-Face Texture Mapping faceInfoSize Code Execution Vulnerability

Talos has discovered a stack-based buffer overflow in PTEX that could potentially allow a remote attacker to execute arbitrary code on affected systems. This vulnerability was discovered by Tyler Bohan of Cisco Talos. The vulnerability manifests when a file is read due to lack of proper parameter checking. The value of the ‘faceInfoSize’ parameter is not properly checked for validity. Talos recommends installing this update as quickly as possible. The library has been incorporated in several other applications such as Pixar’s RenderMan, giving it a large install base.”]

Source: https://blog.talosintelligence.com/2018/01/ptex-rce-vuln.html

Exit mobile version