CVE-2020-28591: Input Validation
Published Mar 3, 2021
·Updated
An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
4 affected components
Slic3r libslic3r=1.3.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Event History
Mar 3, 2021
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-28591?
The severity of CVE-2020-28591 is high.
2
What software versions are affected by CVE-2020-28591?
Slic3r libslic3r 1.3.0 and Fedora versions 32, 33, and 34 are affected by CVE-2020-28591.
3
How can an attacker exploit CVE-2020-28591?
An attacker can exploit CVE-2020-28591 by providing a specially crafted AMF file.
4
What is the impact of CVE-2020-28591?
CVE-2020-28591 can lead to information disclosure.
5
Are there any references available for CVE-2020-28591?
Yes, references for CVE-2020-28591 are available at the following URLs: [URL1], [URL2], [URL3].