CVE-2021-21772
Dashboard / Vulnerabilities / CVE-2021-21772
CVE-2021-21772
Summary:
Details: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
References: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHMMHD2EOMIVJ7EKZTJJMX4C7E6ZRWDL/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPBS642OYVA6DUKK3HZHEINVWEDZSMEU/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDGGB65YBQL662M3MOBNNJJNRNURW4TG/, https://security.gentoo.org/glsa/202208-01, https://www.debian.org/security/2021/dsa-4887, https://talosintelligence.com/vulnerability_reports/TALOS-2020-1226, https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1226
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
