PT-2022-12435 · Slic3R+1 · Libslic3R+1
Eldstal
·
Published
2022-01-25
·
Updated
2022-01-28
·
CVE-2021-45847
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Slic3r libslic3r version 1.3.0
Description
The issue is related to several missing input validations in the 3MF parser component of Slic3r libslic3r. This can allow an attacker to cause an application crash using a crafted 3MF input file.
Recommendations
For Slic3r libslic3r version 1.3.0, consider disabling the 3MF parser component until a patch is available to prevent potential application crashes from crafted 3MF input files.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Libslic3R