CVE-2020-28598: High severity prusaslicer vulnerability
Published Jul 8, 2021
·Updated
An out-of-bounds write vulnerability exists in the Admesh stlfixnormaldirections() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted AMF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Prusa3d Prusaslicer=2.2.0
Event History
Jul 8, 2021
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-28598?
CVE-2020-28598 is an out-of-bounds write vulnerability in the Admesh stl_fix_normal_directions() functionality of Prusa Research PrusaSlicer.
2
How does CVE-2020-28598 manifest?
CVE-2020-28598 can be exploited by providing a specially crafted AMF file, which can lead to code execution.
3
Which software versions are affected by CVE-2020-28598?
PrusaSlicer version 2.2.0 is affected by CVE-2020-28598.
4
What is the severity of CVE-2020-28598?
CVE-2020-28598 has a severity rating of 7.8 (high).
5
How can CVE-2020-28598 be mitigated?
To mitigate CVE-2020-28598, users are advised to update to a non-vulnerable version of PrusaSlicer.