Lucene search

K
cvelistTalosCVELIST:CVE-2020-35633
HistoryAug 30, 2021 - 12:00 a.m.

CVE-2020-35633

2021-08-3000:00:00
CWE-129
talos
www.cve.org
5
code execution
vulnerability
nef polygon-parsing
cgal libcgal
out-of-bounds read
type confusion
malicious input

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.007

Percentile

81.2%

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_sface() store_sm_boundary_item() Edge_of.A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "CGAL Project",
    "versions": [
      {
        "version": "CGAL Project libcgal CGAL-5.1.1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.007

Percentile

81.2%