UBUNTU-CVE-2020-35636
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-35636
Summary:
Details: A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() sfh->volume() OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2020-35636, https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225, https://github.com/CGAL/cgal/issues/5345, https://github.com/CGAL/cgal/pull/5371, https://github.com/CGAL/cgal/issues/5514, https://www.cve.org/CVERecord?id=CVE-2020-35636
Affected packages
Package
Name: cgal
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
