CVE-2020-35634: critical vulnerability in CGAL Project
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A vulnerability in CGAL's polygon parsing allows attackers to crash the program or run malicious code by providing a specially crafted file. The flaw occurs when the software reads polygon data without properly checking boundaries, leading to memory corruption.
An out-of-bounds read vulnerability exists in CGAL-5.1.1's Nef_S2/SNC_io_parser.h during polygon file parsing, specifically in the read_sface() function when processing boundary entry objects. A malformed input file can trigger memory access violations and type confusion, enabling arbitrary code execution; the attack vector is file-based with minimal pre-conditions (user must open the crafted file).