CVE-2020-28595: High severity prusaslicer vulnerability
An out-of-bounds write vulnerability exists in the Obj.cpp loadobj() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted obj file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28595?
CVE-2020-28595 is an out-of-bounds write vulnerability in the Obj.cpp load_obj() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856).
How does CVE-2020-28595 affect PrusaSlicer?
CVE-2020-28595 allows an attacker to execute code by providing a specially crafted obj file to the PrusaSlicer software.
What is the severity of CVE-2020-28595?
The severity of CVE-2020-28595 is high, with a CVSS score of 7.8.
How can I fix CVE-2020-28595?
To fix CVE-2020-28595, users should update to a patched version of PrusaSlicer.
Where can I find more information about CVE-2020-28595?
More information about CVE-2020-28595 can be found at the following link: https://talosintelligence.com/vulnerability_reports/TALOS-2020-1219