CVE-2020-28606: Out-of-bounds Read
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef2/PMioparser.h PMioparser<PMDEC>::readhedge() e->setface().
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28606?
CVE-2020-28606 has been classified as a high severity vulnerability due to its potential for code execution.
How do I fix CVE-2020-28606?
To fix CVE-2020-28606, upgrade to CGAL version 5.1.2 or later, which addresses these vulnerabilities.
What types of systems are affected by CVE-2020-28606?
CVE-2020-28606 affects CGAL version 5.1.1 on Debian 10.0 and related systems using the library.
What actions can attackers take using CVE-2020-28606?
Attackers can exploit CVE-2020-28606 to execute arbitrary code through specially crafted polygon files.
Is CVE-2020-28606 related to other vulnerabilities?
CVE-2020-28606 may have similarities with other vulnerabilities involving code execution through malformed input, highlighting a pattern in the library's handling of such data.