Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2021-44961
HistoryMar 01, 2022 - 2:15 a.m.

CVE-2021-44961

2022-03-0102:15:07
Debian Security Bug Tracker
security-tracker.debian.org
22
slic3r
memory leakage
vulnerability
stl files
attacker
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.7%

A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability.

OSVersionArchitecturePackageVersionFilename
Debian12allslic3r<= 1.3.0+dfsg1-5slic3r_1.3.0+dfsg1-5_all.deb
Debian11allslic3r<= 1.3.0+dfsg1-5slic3r_1.3.0+dfsg1-5_all.deb
Debian999allslic3r<= 1.3.0+dfsg1-5slic3r_1.3.0+dfsg1-5_all.deb

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.7%

Related for DEBIANCVE:CVE-2021-44961