CVE-2020-28601
CRITICAL
10.0
CVSS 3.0
Description
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| n/a | CGAL | — | CGAL Project libcgal CGAL-5.1.1 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-129 | cna | CWE-129: Improper Validation of Array Index |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (6)
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225
- FEDORA-2021-0d42c7cb33 https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4J344OKKDLPRN422OYRR46HDEN6MM6P/
- FEDORA-2021-9de542ab4c https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NB5SF5OJR2DSV7CC6U7FVW5VJSJO5EKV/
- [debian-lts-announce] 20210505 [SECURITY] [DLA 2649-1] cgal security update https://lists.debian.org/debian-lts-announce/2021/05/msg00002.html
- [debian-lts-announce] 20221206 [SECURITY] [DLA 3226-1] cgal security update https://lists.debian.org/debian-lts-announce/2022/12/msg00011.html
- GLSA-202305-34 https://security.gentoo.org/glsa/202305-34