Описание
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | not-affected | 1.8.1+ds-4 |
| esm-apps/focal | released | 1.8.1+ds-3ubuntu0.2 |
| esm-apps/jammy | not-affected | 1.8.1+ds-4 |
| esm-infra-legacy/trusty | DNE | |
| focal | released | 1.8.1+ds-3ubuntu0.2 |
| groovy | ignored | end of life |
| hirsute | ignored | end of life |
| impish | ignored | end of life |
| jammy | not-affected | 1.8.1+ds-4 |
Показывать по
EPSS
6.8 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
A use-after-free vulnerability exists in the NMR::COpcPackageReader::r ...
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Уязвимость функции NMR :: COpcPackageReader :: releaseZIP () библиотеки 3MF Consortium lib3mf, позволяющая нарушителю выполнить произвольный код
EPSS
6.8 Medium
CVSS2
8.1 High
CVSS3