[3dprinter-general] Bug#985620: slic3r: CVE-2020-28591

Salvatore Bonaccorso carnil at debian.org
Sat Mar 20 20:41:53 GMT 2021


Source: slic3r
Version: 1.3.0+dfsg1-3.2
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Control: found -1 1.3.0+dfsg1-3

Hi,

The following vulnerability was published for slic3r.

CVE-2020-28591[0]:
| An out-of-bounds read vulnerability exists in the AMF File
| AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0
| and Master Commit 92abbc42. A specially crafted AMF file can lead to
| information disclosure. An attacker can provide a malicious file to
| trigger this vulnerability.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-28591
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28591
[1] https://talosintelligence.com/vulnerability_reports/TALOS-2020-1215
[2] https://github.com/slic3r/Slic3r/issues/5061
[3] https://github.com/slic3r/Slic3r/pull/5063

Regards,
Salvatore



More information about the 3dprinter-general mailing list