PT-2023-13500 · Libslic3R+1 · Libslic3R+1

Francesco Benvenuto

·

Published

2023-04-20

·

Updated

2023-05-02

·

CVE-2022-36788

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libslic3r version 1.3.0 libslic3r Master Commit b1a5500
Description A heap-based buffer overflow issue exists in the TriangleMesh clone functionality. This can be triggered by a specially-crafted STL file, leading to a heap buffer overflow. An attacker can exploit this by providing a malicious file.
Recommendations For libslic3r version 1.3.0, consider disabling the TriangleMesh clone functionality until a patch is available. For libslic3r Master Commit b1a5500, restrict the use of the TriangleMesh clone functionality to minimize the risk of exploitation. Avoid using malicious STL files in the affected functionality until the issue is resolved.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-36788

Affected Products

Debian
Libslic3R