PT-2021-11561 · Slic3R · Slic3R

Published

2021-03-03

·

Updated

2022-08-31

·

CVE-2020-28591

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Slic3r libslic3r version 1.3.0 Slic3r libslic3r Master Commit 92abbc42
Description: An out-of-bounds read issue exists in the AMF File AMFParserContext::endElement() functionality. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this issue.
Recommendations: For Slic3r libslic3r version 1.3.0, consider avoiding the use of the AMFParserContext::endElement() function until a patch is available. For Slic3r libslic3r Master Commit 92abbc42, restrict the processing of AMF files to minimize the risk of exploitation. As a temporary workaround, consider disabling the AMFParserContext::endElement() function until a patch is available.

Exploit

Fix

Out of bounds Read

RCE

Weakness Enumeration

Related Identifiers

CVE-2020-28591
MGASA-2021-0276

Affected Products

Slic3R