Описание
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Ссылки
- Patch
- ExploitTechnical DescriptionThird Party Advisory
- Patch
- ExploitTechnical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:admesh_project:admesh:0.98.4:*:*:*:*:*:*:*
cpe:2.3:a:admesh_project:admesh:2022-11-18:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:slic3r:libslic3r:b1a5500:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00096
Низкий
6.5 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-118
CWE-129
Связанные уязвимости
CVSS3: 6.5
ubuntu
почти 3 года назад
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
EPSS
Процентиль: 27%
0.00096
Низкий
6.5 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-118
CWE-129