CVE-2020-35633: Out-of-bounds Read
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in NefS2/SNCioparser.h SNCioparser<EW>::readsface() storesmboundaryitem() Edgeof.A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35633?
CVE-2020-35633 has been classified as a high-severity vulnerability due to the potential for code execution.
How do I fix CVE-2020-35633?
The fix for CVE-2020-35633 involves updating the CGAL library to version 5.1.3 or later.
What software is affected by CVE-2020-35633?
CVE-2020-35633 affects CGAL version 5.1.1 and Debian GNU/Linux version 10.0.
What kind of vulnerability is CVE-2020-35633?
CVE-2020-35633 is a code execution vulnerability stemming from an out-of-bounds read issue.
Can CVE-2020-35633 be exploited remotely?
Yes, CVE-2020-35633 can potentially be exploited remotely by using a specially crafted malformed file.