A code execution vulnerability exists in the Nef polygon...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 30, 2023
Description
Published by the National Vulnerability Database
Aug 30, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
May 30, 2023
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface() store_sm_boundary_item() Sloop_of OOB read. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger this vulnerability.
References