CVE-2020-28601: Out-of-bounds Read
Published Mar 4, 2021
·Updated
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef2/PMioparser.h PMioparser::readvertex() Faceof[] OOB read. An attacker can provide malicious input to trigger this vulnerability.
Affected Software
5 affected components
CGAL Computational Geometry Algorithms Library=5.1.1
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Mar 4, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this code execution vulnerability?
The vulnerability ID for this code execution vulnerability is CVE-2020-28601.
2
What is the severity level of CVE-2020-28601?
CVE-2020-28601 has a severity level of critical (9.8).
3
Which software versions are affected by CVE-2020-28601?
CGAL libcgal CGAL-5.1.1, Fedoraproject Fedora 33 and 34, Debian Debian Linux 9.0 and 10.0 are affected by CVE-2020-28601.
4
What is the CWE ID associated with CVE-2020-28601?
CVE-2020-28601 is associated with CWE-129 and CWE-125.
5
How can I fix the code execution vulnerability CVE-2020-28601?
To fix the code execution vulnerability CVE-2020-28601, it is recommended to update to the latest version of the affected software.