CVE-2020-28631: Out-of-bounds Read
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in NefS2/SNCioparser.h SNCioparser<EW>::readsedge() seh->source().
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28631?
CVE-2020-28631 is a code execution vulnerability in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
What is the severity of CVE-2020-28631?
CVE-2020-28631 has a severity rating of critical with a score of 8.8.
How does CVE-2020-28631 impact the affected software?
CVE-2020-28631 can lead to code execution by exploiting out-of-bounds read and type confusion vulnerabilities in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
Which software versions are affected by CVE-2020-28631?
CGAL libcgal version 5.1.1 and Debian Linux version 10.0 are affected by CVE-2020-28631.
How can I fix CVE-2020-28631?
To fix CVE-2020-28631, update CGAL libcgal to a version that is not affected by the vulnerability.