ZeroHour

CVE-2020-35636

PoC
CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh->volume() OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.

Vendors
cgaldebian
Products
computational geometry algorithms library, debian linux
Weakness
CWE-129, CWE-125, CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.