PT-2022-12268 · Libslic3R+2 · Libslic3R+2
Published
2022-03-01
·
Updated
2022-03-24
·
CVE-2021-44962
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Slic3r libslic3r version 1.3.0
Slic3r libslic3r Master Commit b1a5500
Description
An out-of-bounds read issue exists in the GCode::extrude() functionality. A specially crafted stl file could lead to information disclosure. An attacker can provide a malicious file to trigger this issue.
Recommendations
For Slic3r libslic3r version 1.3.0, consider avoiding the use of the GCode::extrude() functionality until a patch is available.
For Slic3r libslic3r Master Commit b1a5500, restrict the processing of stl files from untrusted sources to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Slic3R
Libslic3R