CVE-2020-28594: Use After Free
A use-after-free vulnerability exists in the 3MFImporter::handleendmodel() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28594?
The severity of CVE-2020-28594 is high with a value of 7.8.
What is the affected software of CVE-2020-28594?
The affected software of CVE-2020-28594 is Prusa Research PrusaSlicer version 2.2.0.
How does the vulnerability CVE-2020-28594 occur?
The vulnerability CVE-2020-28594 occurs due to a use-after-free vulnerability in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer.
What is the impact of the vulnerability CVE-2020-28594?
The vulnerability CVE-2020-28594 can lead to code execution when a specially crafted 3MF file is provided.
How can the vulnerability CVE-2020-28594 be exploited?
The vulnerability CVE-2020-28594 can be exploited by providing a malicious 3MF file.