UBUNTU-CVE-2020-28605
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-28605
Summary:
Details: Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read exists in Nef_2/PM_io_parser.h PM_io_parser<PMDEC>::read_hedge() e->set_vertex().
References: https://ubuntu.com/security/CVE-2020-28605, https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225, https://www.cve.org/CVERecord?id=CVE-2020-28605
Affected packages
Package
Name: cgal
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
