Out-of-bounds read in cgal - CVE-2020-28626
Published: March 2, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in Nef_S2/SNC_io_parser.h SNC_io_parser::read_facet() fh->incident_volume(). A remote attacker can use a specially crafted file, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Gentoo Linux
sci-mathematics/cgal
How to mitigate CVE-2020-28626
sci-mathematics/cgal - update to 5.4.1