Lucene search

K
osvGoogleOSV:CVE-2020-28599
HistoryFeb 24, 2021 - 4:15 p.m.

CVE-2020-28599

2021-02-2416:15:14
Google
osv.dev
4
buffer overflow
openscad
code execution
stl file
vulnerability
import_stl functionality

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

59.0%

A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

59.0%