CVE-2022-38072: Out-of-bounds Read
An improper array index validation vulnerability exists in the stlfixnormaldirections functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-38072?
CVE-2022-38072 is an improper array index validation vulnerability in the stl_fix_normal_directions functionality of ADMesh.
What is the severity of CVE-2022-38072?
CVE-2022-38072 has a severity rating of 8.8 (high).
What software is affected by CVE-2022-38072?
The affected software includes ADMesh versions 0.98.4 and 2022-11-18, as well as Slic3r libslic3r version b1a5500.
What can an attacker do with CVE-2022-38072?
An attacker can provide a specially-crafted stl file to trigger a heap buffer overflow.
Where can I find more information about CVE-2022-38072?
More information about CVE-2022-38072 can be found on the GitHub commit and Talos Intelligence vulnerability reports: [GitHub](https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5f), [Talos Intelligence](https://talosintelligence.com/vulnerability_reports/TALOS-2022-1594)