9.8
CVSSv3

CVE-2020-28601

Published: 04/03/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cgal computational geometry algorithms library 5.1.1

fedoraproject fedora 33

fedoraproject fedora 34

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #985671 CVE-2020-35636 CVE-2020-35628 CVE-2020-28636 CVE-2020-28601 Package: src:cgal; Maintainer for src:cgal is Joachim Reichel <reichel@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 21 Mar 2021 19:06:02 UTC Severity: grave Tags: pending, security, upstream ...
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-511 An out of bounds read vulnerability exists in Nef_2/PM_io_parserh PM_io_parser::read_vertex() Face_of[] An attacker can provide malicious input to trigger this vulnerability ...