CVE-2020-28623: critical vulnerability in CGAL Project libcgal
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in CGAL's polygon file parser allows attackers to craft malicious files that trigger out-of-bounds memory reads and type confusion, potentially leading to arbitrary code execution on systems processing these files.
CVE-2020-28623 exploits improper bounds checking in the Nef polygon-parsing functionality (specifically SNC_io_parser<EW>::read_facet() in Nef_S2/SNC_io_parser.h), allowing specially crafted malformed input files to cause out-of-bounds reads and type confusion. An attacker can supply malicious polygon data to trigger code execution; no authentication or special privileges are required if the application processes untrusted files.
In the same product, most dangerous first.