Out-of-bounds read in cgal - CVE-2020-28636
Published: March 2, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin(). A remote attacker can use a specially crafted file, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Gentoo Linux
Fedora
CGAL
sci-mathematics/cgal
How to mitigate CVE-2020-28636
CGAL - addressed in versions 5.1.3-1.fc33, 5.2.1-1.fc34
sci-mathematics/cgal - update to 5.4.1