CVE-2020-28616: Out-of-bounds Read
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in NefS2/SNCioparser.h SNCioparser<EW>::readvertex() vh->sfacesbegin().
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28616?
The severity of CVE-2020-28616 is critical with a CVSS score of 8.8.
How can I mitigate the code execution vulnerabilities in CGAL libcgal version 5.1.1?
To mitigate the vulnerabilities, update to a patched version of CGAL libcgal or apply the necessary security patches provided by the vendor.
What software versions are affected by CVE-2020-28616?
The vulnerabilities in CVE-2020-28616 affect CGAL libcgal version 5.1.1 and Debian Linux version 10.0.
What type of vulnerabilities exist in the Nef polygon-parsing functionality of CGAL libcgal?
The vulnerabilities include out-of-bounds read, type confusion, and code execution through specially crafted malformed files.