PT-2021-3357 · 3Mf Consortium+2 · Lib3Mf+2
Lilith >_>
·
Published
2021-02-11
·
Updated
2023-07-11
·
CVE-2021-21772
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
3MF Consortium lib3mf version 2.0.0
Description
A use-after-free vulnerability exists in the
NMR::COpcPackageReader::releaseZIP() functionality. This issue is related to the use of memory after it has been freed. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code using a specially crafted 3MF file. An attacker can provide a malicious file to trigger this vulnerability.Recommendations
For version 2.0.0, consider disabling the
NMR::COpcPackageReader::releaseZIP() function until a patch is available to prevent potential exploitation. Restrict access to the lib3mf library to minimize the risk of exploitation. Avoid using specially crafted 3MF files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Lib3Mf