← back
CVE-2020-28601criticalCWE-129

CVE-2020-28601

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 10epss 2.9%
exploitation probability
2.9%top 14% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in CGAL's polygon-parsing tool allows attackers to read memory outside safe boundaries by providing specially crafted input, potentially crashing the application or exposing sensitive data.

Technical detail

An out-of-bounds read vulnerability in Nef_2/PM_io_parser.h's read_vertex() function allows unauthenticated attackers to supply malicious polygon data, triggering memory access beyond allocated buffer bounds. The attack requires no special privileges and results in information disclosure or denial of service.

Summary generated and translated by AI from the official description.
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
n/a · CGAL