CVE-2020-35628
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 10epss 2.9%
exploitation probability
2.9%top 15% of all CVEs
observed exploitation
nono source reports it
In short
A vulnerability in CGAL's polygon-parsing tool allows attackers to crash the program or potentially run malicious code by providing specially crafted input files that cause the software to read memory outside safe boundaries.
Technical detail
An out-of-bounds read vulnerability exists in the Nef polygon parser (SNC_io_parser::read_sloop function) when processing malformed input, allowing an attacker to access invalid memory regions and potentially achieve code execution through crafted polygon data.
Summary generated and translated by AI from the official description.
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An attacker can provide malicious input to trigger this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
n/a · CGALReferences
https://lists.debian.org/debian-lts-announce/2021/05/msg00002.htmlhttps://lists.debian.org/debian-lts-announce/2022/12/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4J344OKKDLPRN422OYRR46HDEN6MM6P/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NB5SF5OJR2DSV7CC6U7FVW5VJSJO5EKV/https://security.gentoo.org/glsa/202305-34https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225